other
- Location
SKILL.md:45- Finding
Unspecified Third-Party Disclosure of User PDF Documents
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 45–46
Vulnerability Type: Unspecified third-party data disclosure
Risk Level: HighVulnerable Code
markdown - Merge multiple user-provided PDF files by uploading them to Cross-Service-Solutions, polling untiTechnical Analysis
The Skill directs the Agent to upload user-provided PDF documents to an external service identified only as
Cross-Service-Solutions. The project does not specify an API endpoint, service operator, privacy policy, data-retention policy, storage location, deletion procedure, or mechanism for obtaining informed user consent.Although the document contains general recommendations to use HTTPS, it does not define or enforce an HTTPS endpoint. It also provides no implementation that would allow reviewers to verify certificate validation, authentication behavior, access controls, request destinations, or handling of uploaded files.
PDF documents can contain personal, financial, legal, medical, or confidential corporate information. Sending them to an unidentified processor creates a material disclosure risk. This finding concerns the documented external-transfer behavior; the project contains no executable implementation proving that an upload actually occurs.
Attack Path
- A user selects local PDF files and invokes the merge Skill.
- The Agent reads the selected documents as part of the documented workflow.
- Following the Skill instructions, the Agent attempts to upload the files to
Cross-Service-Solutions. - The documents leave the user's local trust boundary without a defined destination, verified operator, or explicit consent checkpoint.
- An unknown or compromised recipient could inspect, retain, redistribute, or otherwise process the PDF contents.
- The user receives a job result or download URL but has no documented method to verify deletion of the source files or merged output.
Impact A
...[truncated 583 chars]
- Remediation
View remediation
Remediation Suggestions
- Identify the service operator and document the exact HTTPS API origin.
- Pin or strictly allowlist the permitted hostname and reject redirects to unapproved hosts.
- Require an explicit confirmation immediately before upload that identifies the destination and files being transferred.
- Publish the processor's privacy policy, retention period, deletion procedure, storage jurisdiction, and subprocessors.
- Clearly warn users not to upload sensitive documents unless the service is approved for that data classification.
- Enforce TLS certificate and hostname validation rather than merely recommending HTTPS.
- Minimize server-side retention and automatically delete source documents and generated outputs after a defined period.
- Avoid logging document contents, credentials, signed download URLs, or other sensitive request data.
- Provide a local PDF-merging option so documents do not need to leave the user's system.
- Supply an auditable implementation that validates response types, file sizes, timeouts, authentication, and destination URLs.
