Back to skill

Security audit

Doc2md

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward document-to-Markdown converter, but users should know it uploads documents to MinerU's cloud service and installs an unpinned third-party CLI.

Install only if you are comfortable using MinerU's CLI and cloud processing for the documents you convert. For sensitive files, consider a local-only converter or install the CLI in a sandbox with a pinned, reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Third-Party CLI Dependencies

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Unpinned third-party dependencies
Risk Level: Medium

Vulnerable Code Snippet:

yaml
metadata: {"openclaw":{"emoji":"📑","requires":{"bins":["mineru-open-api"]},"install":[{"id":"npm","kind":"node","package":"mineru-open-api","bins":["mineru-open-api"],"label":"Install via npm"},{"id":"uv","kind":"uv","package":"mineru-open-api","bins":["mineru-open-api"],"label":"Install via uv"},{"id":"go","kind":"go","package":"github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api","bins":["mineru-open-api"],"label":"Install via go install","os":["darwin","linux"]}]}}

Technical Analysis

The installation metadata allows mineru-open-api to be installed from npm, the Python/uv package ecosystem, or a Go module without specifying an immutable version, commit, checksum, or signature. Consequently, the code installed during a future deployment may differ from the code that was reviewed.

Package installers and installed command-line programs can execute code with the privileges of the user or agent performing the installation. If an upstream package, publisher account, repository, release process, or transitive dependency is compromised, a malicious release could execute during installation or when mineru-open-api is invoked.

The audit found no evidence that the currently referenced packages are malicious. The confirmed issue is the absence of dependency integrity and version controls, which leaves the skill exposed to future supply-chain changes.

Attack Path

  1. An attacker compromises a referenced package, its publisher account, its source repository, or a transitive dependency.
  2. The attacker publishes a malicious release under the existing package or module name.
  3. An agent installs the dependency using the unpinned npm, uv, or Go installation definition.
  4. The package manager resolves the mutable package reference to the ...[truncated 891 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin every dependency to a reviewed, exact version. For the Go source, use an immutable reviewed commit or version tag rather than an unresolved module reference.
  • Record and verify package checksums, signatures, lockfile integrity values, or equivalent provenance attestations before installation.
  • Confirm that each package originates from the canonical publisher and repository.
  • Use automated dependency scanning and controlled update procedures. Review and test each version change before updating the pinned reference.
  • Disable package lifecycle scripts where feasible, or perform installation in an isolated build environment with no credentials and minimal filesystem and network access.
  • Run the converter in a sandbox or container with least-privilege permissions and access restricted to the specific input and output files required for conversion.
  • Prefer a centrally reviewed internal package mirror or artifact repository to prevent unexpected upstream changes from reaching production directly.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.