Back to skill

Security audit

signature-splice

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local PDF/signature-image utility; it handles sensitive signature files, but its behavior is purpose-aligned and user-directed.

Install only if you are authorized to place each signature on the target document. Treat source signature images, generated PDFs, and rendered PNG previews as sensitive files; use a private output directory and delete temporary artifacts when no longer needed. This tool creates image-based signature placement and does not provide cryptographic PDF digital signatures or legal consent validation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个“签名图片插入PDF并排版”的技能,核心能力应包括PDF读写、目标区域定位、按顺序放置签名、输出签字版PDF,以及可能的预处理流程。实际代码只是一个独立的预览脚本:收集图片、可选缩放、在纯色背景上纵向拼贴、添加文件名和尺寸文字、保存为单张图片。它确实与“签名图片预处理结果自查”有弱相关性,但这只是辅助预览功能,不是声明中的主要用途。由于代码的主要行为与声明的核心功能显著不同,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This code chunk materially differs from the declared skill purpose. The description promises a workflow that preprocesses signature images and inserts them into PDFs, but the actual script only analyzes image characteristics and prints a JSON report. While some reported properties (frame lines, ink bounding box, polarity, background luminance) could support a preprocessing pipeline, they are only diagnostic helpers and do not themselves perform the advertised signing/composition task. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码块是一个“定位签名插入区域”的辅助工具,核心逻辑是:读取 PDF、查找包含指定锚点文本的文本行、合并页面绘图矩形作为候选框,并计算锚点下方的可用区域。它的主目的与声明中的“预处理签名图片并均匀插入 PDF”明显不同。虽然它与更大签名排版流程相关,属于上游步骤,但单看此代码块,并未实现声明中的关键能力:去背景、裁边、透明化、按顺序均匀插入、写回 PDF、渲染自查。因此描述未准确代表该代码块的实际行为,构成明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个完整的“签名图片插入 PDF”技能,核心能力应包括:处理签名图、定位 PDF 目标区域、将多张签名按顺序均匀排版到 PDF 中,并做插入后的渲染检查。但实际提供的代码文件 preprocess_signatures.py 只负责前处理签名图片,本身与其模块说明也一致:输入图片,输出透明背景、紧裁的 PNG。代码中没有任何 PDF 相关库或逻辑,没有页面坐标、表单区域、版式布局、顺序插入、渲染回读等功能。因此该代码只覆盖了声明中的“预处理(去背景、去截图边框、紧裁、透明化)”这一子步骤,而缺失声明的主要目的和关键能力,属于明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的核心能力是“处理签名图片并将其插入到 PDF 中指定区域”,即生成或编辑 PDF。实际代码的核心行为则是“验证/比对”两个现有 PDF 文件,检查页数、大小、嵌入图片以及文本是否一致。这与声明的主要用途明显不同。虽然声明中提到‘插入后渲染自查’,但该代码并未参与插入过程,也没有围绕签名图片排版开展处理,只是在做结果核验。因此属于实质性用途不符。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README explicitly promotes automated insertion of handwritten or electronic signature images into PDFs, which involves highly sensitive biometric-like personal data and documents that may carry legal significance. Without prominent warnings about authorization, consent, provenance, and secure handling, the skill lowers friction for misuse such as unauthorized document signing, impersonation, or unsafe processing of signature assets.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description is written to trigger on Chinese phrases only, and the rest of the skill examples and terminology are likewise fixed to a single language context. There is no opt-in, alternate locale support, or justification that this skill is intentionally limited to a Chinese-only regional or compliance use case.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill handles sensitive signature images and generates derivative outputs, but the user-facing description does not prominently warn that a new PDF and rendered PNGs containing signature data will be written to disk. This can lead to inadvertent exposure of biometric-like signature artifacts through retained files, synced folders, or shared workspaces.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.