Back to skill

Security audit

Split PDF

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward PDF-splitting API wrapper, but users should know their PDFs or PDF URLs are sent to pdfapihub.com.

Install only if you are comfortable sending PDFs or public PDF URLs to pdfapihub.com and receiving outputs that may be hosted on its CDN. Do not submit confidential, regulated, internal-only, or third-party documents unless you have reviewed and accepted that provider's privacy, retention, and access controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to provide either a public URL to a PDF or the PDF content itself, and to send it to pdfapihub.com, but it does not clearly warn that document contents and source URLs will be transmitted to a third-party service. This can lead to unintentional disclosure of sensitive documents or internal resource locations, especially if users assume processing is local or first-party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The example usage shows direct transmission of user-supplied PDF data or URLs to an external API endpoint. While external transmission is expected for this integration, it still creates a real data-exposure risk because document contents, metadata, and potentially sensitive URLs leave the local trust boundary and are processed by a third party.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

Example Usage

bash
curl -X POST https://pdfapihub.com/api/v1/pdf/split \
  -H "CLIENT-API-KEY: your_api_key" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example shows the PDF is sent to a third-party API for processing and the output is returned as externally hosted URLs, which creates a real data exposure risk for uploaded documents. For a skill described simply as splitting a PDF, this behavior expands data handling beyond local transformation and may surprise users, especially if documents are sensitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill depends on external network processing and third-party hosting even though the stated function is a straightforward document split operation. This increases the attack surface through data transit, vendor trust, retention, and unauthorized access risks without any visible justification or controls in the example.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill sends user-supplied PDF content or a public PDF URL to a third-party service at pdfapihub.com, but the manifest provides no warning, consent flow, or privacy disclosure about external transmission. PDFs often contain sensitive business, legal, financial, or personal data, so silent upload to an external processor creates a meaningful confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON file is a manifest-style example and contains only request/response data, with no indication of when or in what context the skill should activate. For manifest files, missing trigger specificity or activation constraints can lead to overly broad or unintended invocation because there is no explicit scope, trigger list, or exclusion guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
42% confidence
Finding

The natural-language content in this file is entirely English, but it does not explicitly state whether other languages or locales are supported. This is only a potential policy concern if the skill enforces English-only behavior without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.