T01 · Skill Instruction Hijacking
- Location
SKILL.md:31- Finding
Skill-Level Language Directive Overrides Session Behavior
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a legitimate document-to-Markdown helper, but it may send office documents to an external cloud service in situations where the user only asked to read or summarize them.
Install only if you are comfortable sending selected DOCX, PPTX, XLS, or XLSX files or document URLs to MinerU's cloud API. Avoid using it for confidential, regulated, or enterprise documents unless your organization approves that external processing, and prefer confirming each upload before conversion.
SKILL.md:31Skill-Level Language Directive Overrides Session Behavior
SKILL.md:5Unpinned Third-Party CLI Dependencies Permit Unreviewed Supply-Chain Changes
The skill's activation guidance is broad enough to match generic requests to read, extract, summarize, or analyze office documents, which can cause the agent to invoke this skill in situations where users may not expect cloud processing. Because the skill supports direct URL input and explicitly uploads documents to a third-party service without authentication, over-triggering increases the chance of unintended data disclosure or use on sensitive files.
No suspicious patterns detected.