Back to skill

Security audit

PDF文档工具(免费版)

Security checks across malware telemetry and agentic risk

Overview

The skill is a plausible PDF helper, but its instructions broaden into generic command, network, API, and file-processing behavior beyond the stated PDF purpose.

Review this skill before installing. Use it only for explicit PDF tasks, avoid allowing generic shell commands or outbound API/network use unless you separately approve the action, and specify output paths so generated or merged files do not overwrite important documents.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The skill is presented as a PDF-processing tool, but the documentation broadens it into generic API, network, and command-execution capabilities. This scope expansion can cause an agent to invoke the skill for unrelated tasks and perform higher-risk actions than the user would reasonably expect, increasing the chance of unintended data access, command execution, or network interaction.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The documentation claims API integration and network communication features that are not justified by the stated purpose of a PDF document tool. In an agentic environment, such claims can legitimize unnecessary outbound communication, which creates risk of data exfiltration, fetching untrusted content, or widening the operational scope beyond document processing.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The top-level description is broad enough to overlap with many ordinary document-processing requests, which can cause over-triggering in an agent routing system. Because the skill has read/exec/write-related affordances, overly broad activation increases the risk of it being selected when a safer, narrower skill or no tool use would have been more appropriate.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger phrases are generic and do not define when the skill should or should not activate. In practice, that increases the likelihood of broad routing to a skill that can create, overwrite, split, export, and execute helper operations on files, potentially causing unintended file modifications or disclosure.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes powerful PDF operations but does not prominently warn that they may create, overwrite, split, merge, or export user files. In an automated agent setting, missing mutation/disclosure warnings reduce informed consent and make accidental destructive changes or unintended data propagation more likely.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.