T09 · Insecure Skill Coding Practices
- Location
scripts/process.mjs:135- Finding
Shell Command Injection Through a User-Controlled PDF Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This document-processing skill is transparent in purpose, but a serious command-injection bug could let a maliciously named PDF run commands on the user's machine.
Review this skill before installing. It should not be used on PDFs or filenames from untrusted sources until the pdftotext invocation is changed to a non-shell API such as execFileSync or spawnSync with argument arrays. Also expect limited functionality: translation and several advertised formats are not actually implemented, and processed document contents may be written to console or to the chosen output file.
scripts/process.mjs:135Shell Command Injection Through a User-Controlled PDF Path
The script builds a shell command with user-controlled input and executes it via execSync. Although the filename is wrapped in double quotes, shell metacharacters such as embedded quotes or command substitution can still break out or be evaluated, creating a command-injection risk in a skill that processes untrusted documents.
The markdown describes extracting text, entities, summaries, translations, and reports from user documents, which commonly contain sensitive personal, financial, or business information. However, it provides no warning about privacy implications, handling of confidential files, or the need to review outputs before sharing.
The default option 'to: zh' makes translation output target Chinese unless the user overrides it. This imposes a specific language choice by default rather than prompting or honoring user/system preferences.
The script hard-codes the locale 'zh-CN' when generating timestamps, and the user-facing help and output strings are entirely in Chinese. This enforces a specific language/locale experience without offering the user a choice, which matches the language/locale policy violation criteria.
The manifest description promises '多语言翻译' as a supported document-processing capability. However, translateDocument explicitly states that translation API integration is not implemented and returns the original extracted text instead of translated output, creating a clear mismatch between the advertised skill behavior and actual functionality.
The natural-language description and usage guidance are presented entirely in Chinese, which can amount to a language-policy issue when no user opt-in or alternative locale is offered. There is also no indication that the skill is intentionally restricted to a Chinese-speaking or region-specific audience.
Detected: suspicious.dangerous_exec