Back to skill

Security audit

PDF文档工具(专业版)

Security checks across malware telemetry and agentic risk

Overview

This PDF skill mostly matches its purpose, but it asks for broad file and command authority and does not clearly limit writes, callbacks, or audit data.

Review before installing. Use it only with documents you are comfortable letting an agent read and rewrite, and require explicit input files, output files, and confirmation before merge, split, watermark, encryption, OCR, audit export, or callback/webhook use.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation language is broad enough to match many ordinary document or file-handling requests, increasing the chance the skill is invoked when the user did not intend powerful file-processing and command-execution behavior. Because the skill advertises read, write, and exec capabilities, overbroad triggering materially raises the risk of unintended file access or modification.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Generic trigger phrases like extracting text or merging files are too unspecific for a skill with file modification and execution capabilities. This can cause accidental invocation on ambiguous requests and lead to unintended processing of sensitive local documents or changes to user files.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill documents creation and modification operations such as merge, split, watermark, encryption, and export, but does not prominently warn about overwriting existing files or altering source documents. In a skill with write capability, lack of overwrite safeguards can lead to data loss, corruption, or unintended modification of important documents.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill includes audit reporting, callback URLs, and webhook-style completion notifications without clearly warning that document metadata, processing status, or extracted content could be transmitted or stored externally. For document-processing workflows, this creates meaningful privacy and data-governance risk, especially when handling confidential PDFs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.