Back to skill

Security audit

Knowledge Cards Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently turns user-provided text or local documents into study cards, with a minor dependency-hardening concern for PDF support.

Install this if you want local document-to-card generation. For PDF use, prefer installing dependencies in a virtual environment, keep pypdf updated through a reviewed version, and avoid processing untrusted or unusually large PDFs without resource limits.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:1
Finding

Unbounded Third-Party Dependency Version

Content
View full analysis

Vulnerability Details

File Location: scripts/requirements.txt:1; installation instructions at SKILL.md:43-47
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

scripts/requirements.txt:1:

text
pypdf>=4.0.0

SKILL.md:43-47:

markdown
PDF text extraction requires the `pypdf` Python library. Install it before
using the PDF feature:

pip install -r skills/make-knowledge-cards/scripts/requirements.txt

text

Technical Analysis

The requirements file specifies only a minimum acceptable version of pypdf. Consequently, package resolution can install any later release available from the configured package index. The Skill does not constrain installation to a reviewed version and does not verify package integrity with cryptographic hashes.

This is a supply-chain hardening weakness rather than evidence that the current pypdf package is malicious. However, if the package, a future release, the configured package index, or the dependency resolution environment were compromised, the installation could introduce executable code that was not present during the Skill audit. Package installation and subsequent import occur with the privileges of the user running the Skill.

Attack Path

  1. A user requests PDF-based knowledge-card generation.
  2. The environment does not have pypdf installed.
  3. Following SKILL.md, the user or agent runs the documented pip install command.
  4. The package resolver selects an uncontrolled version satisfying pypdf>=4.0.0.
  5. If that selected release or package source has been compromised, malicious installation or runtime code executes under the invoking user's account.
  6. On import by scripts/extract_pdf.py, malicious dependency code could access the selected PDF and other resources available to that account.

Impact Assessment

Exploitation could obtain the same privileges and file ...[truncated 702 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the lower-bound requirement with an exact, reviewed version, such as pypdf==X.Y.Z.
  2. Generate a lock file containing cryptographic hashes and install with hash verification, for example through pip-compile --generate-hashes followed by pip install --require-hashes.
  3. Review transitive dependencies whenever the lock file is updated.
  4. Use a trusted package index and disable unexpected fallback indexes or untrusted mirrors.
  5. Install the dependency inside an isolated virtual environment under a non-privileged account.
  6. Update the pinned version periodically after security review and vulnerability scanning rather than accepting all future releases automatically.
  7. Avoid performing dependency installation automatically; require explicit user confirmation before running package-management commands.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to produce output in Chinese or English solely based on the detected source text language or dominant language. This imposes a language choice without explicitly offering the user a choice or opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The default prompt is generic enough that the skill may be invoked for broad summarization-style requests without sufficiently constraining the input type or output boundaries. While this is not directly malicious, overly broad triggering can cause the wrong skill to activate on unrelated content, increasing the chance of unintended file/document processing or user confusion about what the agent will do.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes very generic English phrases like "study cards" and especially "flashcards," which can match ordinary user requests that are not specifically intended for this skill. Overly broad activation can cause the agent to invoke this skill in the wrong context, leading to unintended document processing or inappropriate routing of user input.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified as pypdf>=4.0.0, which allows installation of any newer version and does not guarantee a reproducible or reviewed package version. In a skill that processes user-supplied PDF documents, this increases supply-chain and stability risk because future vulnerable or breaking releases could be pulled in without review.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
pypdf>=4.0.0

Unverifiable Dependency: pypdf has 16 known advisory(ies) (CVE-2026-84310 (pypdf: Possible long runtimes/large memory usage when retrieving outlines); CVE-2026-48156 (pypdf: Possible long runtimes for zero-only width values in cross-reference stre); CVE-2026-24688 (pypdf has possible Infinite Loop when processing outlines/bookmarks) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

pypdf has multiple known advisories, many involving denial-of-service conditions such as excessive runtime, infinite loops, or high memory use when parsing malformed PDFs. Because the manifest does not pin to a known-safe version, and this skill explicitly handles PDF input from users, an attacker could supply a crafted PDF that triggers a vulnerable parser version and causes service degradation or resource exhaustion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.