Back to skill

Security audit

PDF工具包(专业版)

Security checks across malware telemetry and agentic risk

Overview

This PDF toolkit skill asks for file and command access that fits its stated PDF-processing purpose, with no evidence of hidden exfiltration or persistence.

Before installing, treat it as a local file-modifying PDF assistant: use explicit output paths, keep backups of important PDFs, avoid batch operations on sensitive folders without review, and do not use the example default password for encryption.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrases are broad enough to match ordinary PDF-related user requests, which increases the chance the skill will activate and perform file-modifying actions without clear user intent boundaries. In a skill with Read/Write/Edit/Bash permissions and destructive operations like overwrite, split, compress, and encrypt, overbroad invocation can lead to unintended file changes or processing of sensitive documents.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill exposes file-writing and potentially destructive PDF operations without prominent warnings, safeguards, or confirmation requirements. Given the declared Write/Edit/Bash tools and operations such as merge, split, compress, encrypt, and watermark, a user could unintentionally overwrite files, corrupt outputs, or modify sensitive documents without realizing the consequences.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.