Back to skill

Security audit

智能文档处理助手

Security checks for vulnerabilities and agentic risk

Overview

This document-processing skill is transparent in purpose, but a serious command-injection bug could let a maliciously named PDF run commands on the user's machine.

Review this skill before installing. It should not be used on PDFs or filenames from untrusted sources until the pdftotext invocation is changed to a non-shell API such as execFileSync or spawnSync with argument arrays. Also expect limited functionality: translation and several advertised formats are not actually implemented, and processed document contents may be written to console or to the chosen output file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/process.mjs:135
Finding

Shell Command Injection Through a User-Controlled PDF Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script builds a shell command with user-controlled input and executes it via execSync. Although the filename is wrapped in double quotes, shell metacharacters such as embedded quotes or command substitution can still break out or be evaluated, creating a command-injection risk in a skill that processes untrusted documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown describes extracting text, entities, summaries, translations, and reports from user documents, which commonly contain sensitive personal, financial, or business information. However, it provides no warning about privacy implications, handling of confidential files, or the need to review outputs before sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default option 'to: zh' makes translation output target Chinese unless the user overrides it. This imposes a specific language choice by default rather than prompting or honoring user/system preferences.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script hard-codes the locale 'zh-CN' when generating timestamps, and the user-facing help and output strings are entirely in Chinese. This enforces a specific language/locale experience without offering the user a choice, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest description promises '多语言翻译' as a supported document-processing capability. However, translateDocument explicitly states that translation API integration is not implemented and returns the original extracted text instead of translated output, creating a clear mismatch between the advertised skill behavior and actual functionality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language description and usage guidance are presented entirely in Chinese, which can amount to a language-policy issue when no user opt-in or alternative locale is offered. There is also no indication that the skill is intentionally restricted to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/process.mjs:138