Back to skill

Security audit

Word Converter

Security checks for vulnerabilities and agentic risk

Overview

This Word conversion skill is coherent, but it asks users to install an unpinned global npm tool and may process documents through MinerU, so it should be reviewed before installation.

Install only if you are comfortable with a globally installed third-party npm CLI and with Word document contents being handled by MinerU-related tooling. Prefer a pinned, locally installed package version, avoid elevated privileges, and do not use this on sensitive documents unless you have verified MinerU's privacy and data-handling terms.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Global npm Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35-39
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Medium

Vulnerable Code

markdown
## Installation

```bash
npm install -g mineru-open-api
text

### Technical Analysis

The installation instructions require users to install `mineru-open-api` globally from the npm registry without specifying a reviewed version, integrity hash, lockfile, or verified source repository. Consequently, the package content retrieved during installation can change after the Skill has been audited.

npm packages can define lifecycle scripts that execute during installation with the privileges of the invoking user. The global `-g` installation also places the executable in a shared command search path, increasing its reach beyond a single project. Although the audited file does not demonstrate that the current package is malicious, this installation method creates an avoidable supply-chain exposure.

### Attack Path

1. An attacker compromises the npm package, its maintainer account, or the package publication process.
2. The attacker publishes a malicious version under the expected package name.
3. A user follows the Skill instructions and runs `npm install -g mineru-open-api`.
4. npm retrieves the latest available package rather than a specifically reviewed release.
5. Malicious lifecycle code can execute during installation under the user's privileges.
6. The globally installed CLI can subsequently execute attacker-controlled behavior whenever the Skill invokes `mineru-open-api`.

### Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation. Potential consequences include access to files and credentials available to that account, modification of user-owned data, malicious document processing, and replacement or misuse of the globally available CLI. Administrative impact would be pos
...[truncated 133 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specific, reviewed version rather than installing the latest release implicitly.
  • Document the authoritative npm package and source-code repository so users can verify package provenance.
  • Provide an integrity verification mechanism, such as a trusted checksum or lockfile generated from the reviewed release.
  • Prefer a project-local installation over npm install -g to reduce system-wide exposure and improve dependency isolation.
  • Consider invoking the pinned local executable through an appropriate package script.
  • Disable npm lifecycle scripts with --ignore-scripts where the package can function without them.
  • Review the selected package version, including its transitive dependencies and lifecycle scripts, before recommending it.
  • Explicitly warn users not to run the installation with administrative privileges.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- document-pipeline
tools:
  - Bash(mineru-open-api:*)
model: claude-3-5-haiku-20241022
---

# Word Document Converter with mineru-open-api

Static analysis

No suspicious patterns detected.