Back to skill

Security audit

Nano Pdf

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed wrapper for using the nano-pdf CLI to edit PDFs, with the main caveat that it installs an unpinned external package.

Before installing, understand that this skill depends on the external `nano-pdf` Python package as resolved by `uv`. Use it on PDFs you are comfortable processing with that CLI, review generated PDFs before distributing them, and prefer a pinned or sandboxed install if your environment handles sensitive documents.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

json
metadata: {"clawdbot":{"emoji":"📄","requires":{"bins":["nano-pdf"]},"install":[{"id":"uv","kind":"uv","package":"nano-pdf","bins":["nano-pdf"],"label":"Install nano-pdf (uv)"}]}}

Technical Analysis

The installation metadata directs uv to install the nano-pdf package without specifying an exact version, integrity hash, or verified artifact source. Dependency resolution can therefore select a package release that was published or modified after this skill was audited.

The dependency's implementation is not included in the project, so its installation behavior, transitive dependencies, and runtime behavior cannot be verified from the audited artifact. Python packages may execute package-controlled code during installation or when their command-line entry points are invoked. This creates a supply-chain trust boundary in which a compromised maintainer account, malicious future release, or compromised transitive dependency could introduce arbitrary behavior.

The audit found no evidence that the skill itself intentionally retrieves a malicious package, and no embedded malicious code, persistence mechanism, privilege escalation, data-exfiltration instruction, or instruction hijacking was present. The risk arises specifically from the unpinned external dependency.

Attack Path

  1. An attacker compromises the upstream nano-pdf distribution channel, maintainer account, or one of its unresolved dependencies.
  2. The attacker publishes a malicious release that remains compatible with the unconstrained package name.
  3. A user or agent installs the skill dependency through the declared uv installation method.
  4. uv resolves and installs the attacker-controlled release because no audited version or artifact hash is enforced.
  5. Malicious code execute ...[truncated 747 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin nano-pdf to a specifically reviewed version rather than resolving the latest available release.
  2. Use a lock file and require cryptographic hashes for the package and all transitive dependencies.
  3. Retrieve artifacts only from a trusted package index or an internally controlled mirror.
  4. Verify package provenance, publisher identity, signatures, and release integrity where supported.
  5. Review the pinned package's source code, build configuration, command entry point, and dependency graph before approval.
  6. Install and execute the utility in a sandbox with minimal filesystem access, no unnecessary credentials, restricted network access, and non-administrative privileges.
  7. Establish an explicit dependency-update process in which new versions are reviewed and tested before the pin and hashes are changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.