Back to skill

Security audit

PDF合并工具

Security checks for vulnerabilities and agentic risk

Overview

This PDF merge skill is mostly aligned with its stated purpose, but it uploads user PDFs to an under-specified external service while requesting broad read, write, and command execution authority.

Review before installing. Use this only for PDFs you are comfortable sending to an external service named Cross-Service-Solutions, and avoid sensitive legal, medical, financial, or confidential business documents unless that service is approved. Prefer a version that limits activation to PDF merging, removes command execution, scopes file access to selected PDFs and a chosen output path, and documents the upload endpoint and data-handling terms.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

other

Error
Location
SKILL.md:45
Finding

Unspecified Third-Party Disclosure of User PDF Documents

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45–46
Vulnerability Type: Unspecified third-party data disclosure
Risk Level: High

Vulnerable Code

markdown
- Merge multiple user-provided PDF files by uploading them to Cross-Service-Solutions,
  polling unti

Technical Analysis

The Skill directs the Agent to upload user-provided PDF documents to an external service identified only as Cross-Service-Solutions. The project does not specify an API endpoint, service operator, privacy policy, data-retention policy, storage location, deletion procedure, or mechanism for obtaining informed user consent.

Although the document contains general recommendations to use HTTPS, it does not define or enforce an HTTPS endpoint. It also provides no implementation that would allow reviewers to verify certificate validation, authentication behavior, access controls, request destinations, or handling of uploaded files.

PDF documents can contain personal, financial, legal, medical, or confidential corporate information. Sending them to an unidentified processor creates a material disclosure risk. This finding concerns the documented external-transfer behavior; the project contains no executable implementation proving that an upload actually occurs.

Attack Path

  1. A user selects local PDF files and invokes the merge Skill.
  2. The Agent reads the selected documents as part of the documented workflow.
  3. Following the Skill instructions, the Agent attempts to upload the files to Cross-Service-Solutions.
  4. The documents leave the user's local trust boundary without a defined destination, verified operator, or explicit consent checkpoint.
  5. An unknown or compromised recipient could inspect, retain, redistribute, or otherwise process the PDF contents.
  6. The user receives a job result or download URL but has no documented method to verify deletion of the source files or merged output.

Impact A

...[truncated 583 chars]

Remediation
View remediation

Remediation Suggestions

  1. Identify the service operator and document the exact HTTPS API origin.
  2. Pin or strictly allowlist the permitted hostname and reject redirects to unapproved hosts.
  3. Require an explicit confirmation immediately before upload that identifies the destination and files being transferred.
  4. Publish the processor's privacy policy, retention period, deletion procedure, storage jurisdiction, and subprocessors.
  5. Clearly warn users not to upload sensitive documents unless the service is approved for that data classification.
  6. Enforce TLS certificate and hostname validation rather than merely recommending HTTPS.
  7. Minimize server-side retention and automatically delete source documents and generated outputs after a defined period.
  8. Avoid logging document contents, credentials, signed download URLs, or other sensitive request data.
  9. Provide a local PDF-merging option so documents do not need to leave the user's system.
  10. Supply an auditable implementation that validates response types, file sizes, timeouts, authentication, and destination URLs.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:22
Finding

Excessive Command Execution and Filesystem Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 22–25
Vulnerability Type: Excessive Agent tool permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

Technical Analysis

The Skill requests general read, exec, and write capabilities. Its stated purpose is to merge selected PDF files through a remote service, but the document does not define any command that legitimately requires arbitrary command execution. It also does not describe a need for unrestricted filesystem writes.

This violates least-privilege principles. An upload workflow ordinarily needs narrowly scoped access to user-selected input files, network access to an allowlisted endpoint, and optionally write access to a designated output location. General command execution can expose all privileges inherited from the Agent process, while broad write access can permit modification of files unrelated to the PDF task.

The file does not contain an explicit malicious command or prompt-hijacking instruction. Consequently, exploitation would depend on another source of attacker-controlled instructions, unsafe Agent behavior, or a future modification to the Skill. Nevertheless, the unnecessary capabilities materially increase the impact of such a compromise.

Attack Path

  1. A user loads the Skill, making read, exec, and write tools available to the Agent.
  2. The Agent processes attacker-influenced input, such as a malicious user instruction, untrusted document-derived text, or a later unsafe Skill instruction.
  3. That input induces the Agent to use exec or write outside the legitimate PDF-merging workflow.
  4. Commands execute with the operating-system privileges inherited by the Agent process, or files writable by that process are modified.
  5. Data accessible to the process could be read or altered, and additional commands could be run within the same privilege boundary.

This project ...[truncated 727 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the exec permission because no documented PDF-merging operation requires arbitrary shell execution.
  2. Restrict read access to PDF files explicitly selected and confirmed by the user.
  3. If output must be downloaded locally, restrict write access to one designated output directory.
  4. Require confirmation before overwriting an existing file.
  5. Replace generic tool permissions with a purpose-built PDF merge or upload tool exposing only required parameters.
  6. Allowlist the external API hostname and deny arbitrary outbound destinations.
  7. Run the Skill in a sandbox without access to credentials, home-directory secrets, source repositories, or system configuration.
  8. Validate file type, size, count, and canonical path before reading or writing.
  9. Treat text extracted from PDFs and remote responses as untrusted data rather than executable Agent instructions.
  10. Add tests confirming that the Skill cannot execute commands or access files outside its approved input and output paths.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description does not prominently and upfront warn that user PDFs are uploaded to an external service for processing. In this context, that omission is significant because PDFs may contain sensitive business, legal, medical, or personal information, and users may unknowingly disclose data to a third party.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation/summary text is overly broad, mixing PDF merge behavior with generic file processing, conversion, and content extraction scenarios. This increases the chance that the agent invokes the skill in contexts beyond its real function, which is especially risky because the skill transmits user files to an external service.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The FAQ states that merged PDFs retain the original files' editability, which is not generally guaranteed and is unsupported by the rest of the skill description. This can mislead users into uploading important documents under false assumptions about output fidelity, potentially affecting legal, business, or archival use of the merged file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill claims it can preserve the original PDF directory structure during a merge, but the described workflow uploads PDFs to an external merge service and returns a single merged output. This is misleading because users may assume structural metadata or organization is retained when it likely is not, causing incorrect reliance for document integrity or compliance-sensitive workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.