Back to skill

Security audit

Pdf Smart Tool Cn 1.1.0

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese PDF-processing skill with expected document features, though users should be careful with sensitive files and irreversible-looking edits.

Install only if you want a Chinese-language PDF assistant. Avoid giving it confidential PDFs, passwords, signatures, certificates, or regulated documents unless you are comfortable with the agent processing that content, and keep backups before decryption, watermark removal, batch renaming, or signing workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises very broad trigger terms like “PDF”, “转换”, and “识别”, which are common in ordinary conversation and can cause unintended activation. That increases the chance users disclose sensitive documents or invoke file-processing behavior without clear intent, especially in chats involving contracts, IDs, invoices, or other confidential material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The OCR functionality is described without any privacy or sensitivity warning, despite being designed to extract text from scanned PDFs and images. Users may submit highly sensitive content such as IDs, contracts, invoices, or medical/financial records without being warned that the tool will process and expose extracted text, increasing privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sections covering decryption, watermark removal, and batch operations present security-impacting and potentially irreversible actions without warnings, guardrails, or authorization checks. This can facilitate removal of document protections at scale, accidental destruction of provenance markings, or mass modification of sensitive files, amplifying both misuse and user harm.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases listed in the description are extremely generic terms such as “PDF”, “转换”, and “识别”, which are likely to appear in ordinary user conversations unrelated to intentionally invoking this skill. That increases the chance of accidental activation on sensitive document workflows, including OCR, decryption, signing, or batch processing, which can expose private files or cause unintended integrity-impacting actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises privacy- and integrity-sensitive capabilities including OCR on uploaded documents, digital signatures, encryption/decryption, watermark removal, and batch processing, but it does not warn users about data sensitivity, document authenticity risks, or irreversible changes. In practice, users may submit confidential PDFs, passwords, signatures, or regulated documents without informed consent or may unintentionally alter legal or evidentiary records.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The skill name and description are centered on a Chinese-language variant ("-cn") and all examples and interface text are presented in Chinese, while no user opt-in or language selection mechanism is documented. Under the policy, forcing a specific language or locale without user choice can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.