Back to skill

Security audit

PDF to Excel

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward PDF-to-Excel API skill, but users should understand their PDFs or PDF URLs are sent to pdfapihub.com.

Install only if you are comfortable sending PDFs, base64 PDF contents, or PDF URLs to pdfapihub.com for conversion. Avoid confidential, regulated, financial, tax, or personal documents unless your organization permits that third-party processing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill requires users to provide a PDF URL, base64 PDF, or uploaded file and directs requests to pdfapihub.com, but it does not clearly warn that user-supplied documents or URLs will be transmitted to a third-party service. This creates a real data-handling and privacy risk, especially for invoices, tax documents, bank statements, and other sensitive PDFs that users may assume are processed locally or within the agent platform.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The example usage shows direct transmission of user-controlled input to an external API endpoint, confirming that document contents or document URLs leave the local trust boundary. In this skill context, that behavior is core functionality rather than hidden exfiltration, but it is still security-relevant because sensitive business and financial documents may be sent to an external processor.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

Example Usage

bash
curl -X POST https://pdfapihub.com/api/v1/convert/pdf/xlsx \
  -H "CLIENT-API-KEY: your_api_key" \
  -H "Content-Type: application/json" \
  -d '{ "url": "https://pdfapihub.com/sample-pdfinvoice-with-image.pdf", "output": "url" }'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a specific transformation behavior: extracting tables and text into an XLSX workbook where each page becomes its own sheet. In the provided file, the skill simply invokes a remote conversion endpoint with a source PDF URL and page range, with no code or parameters demonstrating page-to-sheet mapping or explicit text extraction semantics.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends a user-specified remote PDF URL to an external third-party service, which can expose sensitive document contents and metadata to an untrusted processor outside the user's environment. In a document-conversion skill, this is more dangerous because users may reasonably expect local or bounded processing, while the current design permits arbitrary remote fetches and external data transfer with limited transparency or restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends PDF content or a PDF URL to an external third-party API, but the manifest does not clearly warn that potentially sensitive document data will leave the local trust boundary. This creates a real risk of inadvertent disclosure of confidential files, especially because PDFs often contain regulated, proprietary, or personal information.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description explains capability but does not specify any explicit trigger phrases, activation boundaries, or exclusion conditions, which can make invocation scope ambiguous in systems that derive triggering behavior from manifest text.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.