Back to skill

Security audit

PDF转Word

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local document-conversion helper, but it documents unauthenticated file, download, history, and deletion APIs that could expose or modify converted documents if the service is reachable.

Review this carefully before installing. Only use it with a conversion service bound to localhost or otherwise access-controlled, avoid sensitive documents unless you understand where files and history are stored, and add authentication plus ownership checks before exposing the backend beyond a single trusted user environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/api.md:5
Finding

Unauthenticated Access to Sensitive File and Conversion APIs

Content
View full analysis

Vulnerability Details

File Location: references/api.md, lines 5–10 and 16–95
Vulnerability Type: Missing authentication and object-level authorization
Risk Level: High

Vulnerable Documentation Snippets

markdown
- **Base URL**: `http://localhost:3000/api/v1`
- **认证**: 无
- **文件限制**: 最大 50MB

## 认证

无需认证,所有接口均可直接调用。

The same API specification exposes sensitive file operations without documenting any authentication or authorization requirement:

markdown
### 获取文件信息
GET /api/v1/file/:fileId

### 删除文件
DELETE /api/v1/file/:fileId

### 查询任务状态
GET /api/v1/convert/:taskId

### 下载转换结果
GET /api/v1/convert/:taskId/download

### 转换历史
GET /api/v1/convert/history

Technical Analysis

The documented API explicitly states that no authentication is required and that every endpoint may be invoked directly. Those endpoints expose uploaded-file metadata, file deletion, conversion status, converted-document downloads, and conversion history.

Although references/architecture.md describes JWT support and optional userId ownership fields, the documented API contract does not require a JWT, session, API key, or any other caller identity. It also documents no server-side ownership validation for fileId or taskId. Consequently, object identifiers may function as de facto access tokens, which is not a valid authorization control.

Use of localhost reduces direct remote exposure but does not establish user isolation. Other local users, processes, browser-originated requests, containers with suitable network access, or services exposed through a proxy may still reach the API.

Attack Path

  1. An attacker obtains network access to the service at http://localhost:3000, such as through a local process, shared host, container networking, development proxy, or accidental external binding.
  2. The attacker calls GET /api/v1/convert/history without credentials.
  3. If the endpoint behaves as documented, it returns conversion records and task ...[truncated 1162 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require authentication on every file and conversion endpoint using a securely implemented session, JWT, or equivalent mechanism.
  2. Perform server-side object-level authorization for every supplied fileId and taskId. Confirm that the authenticated principal owns the requested object or has an explicitly assigned administrative role.
  3. Scope /api/v1/convert/history to the authenticated user. Provide a separate, role-protected administrative endpoint if global history is operationally necessary.
  4. Do not treat unguessable identifiers as authorization. Continue using cryptographically random identifiers to reduce enumeration risk, but enforce ownership independently.
  5. Reject anonymous file uploads and task creation, or apply tightly constrained anonymous quotas if anonymous conversion is an intentional product requirement.
  6. Add rate limits, upload quotas, conversion quotas, and audit logging to reduce resource abuse and support incident investigation.
  7. Bind the service to the loopback interface by default. Require explicit configuration before exposing it through a reverse proxy or external interface.
  8. For browser-accessible deployments, enforce a restrictive CORS policy and appropriate CSRF defenses for cookie-authenticated state-changing requests.
  9. Ensure deletion and download operations cannot be performed through another user's identifiers, and add automated tests covering horizontal privilege-escalation attempts.
  10. Update SKILL.md and references/api.md to include the required authorization header or session procedure for every protected request.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

An unauthenticated DELETE /api/v1/file/:fileId endpoint is vulnerable to parameter abuse if file IDs can be discovered, guessed, or harvested from other endpoints. This allows unauthorized deletion of uploaded files, leading to data loss, workflow disruption, and possible deletion of other users' assets.

Content

Scanner excerpt · references/api.md (reported line 40)May include surrounding context.

删除文件

text
DELETE /api/v1/file/:fileId
Response: { success: true }

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase includes the broad term '文档转换' ('document conversion'), which is likely to match many unrelated document tasks beyond PDF-to-Word. Over-broad triggers can cause accidental invocation of this skill on sensitive documents or for unsupported operations, increasing the risk of unnecessary file uploads and exposure to the local conversion service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs users to upload PDF files to a local conversion service without warning that document contents will be transmitted, stored, processed, and potentially retained in task history. For document-conversion workflows, files often contain sensitive personal, legal, financial, or corporate data, so the absence of a disclosure/consent warning materially increases privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is branded and described as a narrowly scoped PDF-to-Word tool, but the documentation exposes a broader document-conversion service with additional formats and engines. This scope mismatch can cause the agent to invoke capabilities the user did not intend, increasing the chance of over-broad file handling, unsupported actions, and accidental exposure of documents to extra processing pipelines such as LibreOffice, ImageMagick, Ghostscript, or other converters.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The usage section tells the model and user that only PDF-to-Word is available, while the same file documents multiple additional conversion types. This inconsistency is dangerous because agents may make incorrect trust and routing decisions, and users may unknowingly trigger broader conversion behavior than expected, causing unintended file processing and policy bypass through ambiguous instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation omits prominent warnings despite describing an unauthenticated service handling file upload, deletion, and history access. This can mislead integrators into treating the API as safe-by-default, increasing the likelihood they expose sensitive document workflows without compensating controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly states that no authentication is required for any endpoint, including file operations and conversion history. That means anyone who can reach the service may be able to upload, inspect, retrieve history about, and potentially manipulate document-processing workflows, creating clear risks of unauthorized access and data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a single-purpose PDF-to-Word converter, but the referenced API exposes many unrelated conversion modes. This broadens the reachable capability surface and can enable use of the skill or its backing service for actions users and policy layers may not expect, undermining least privilege and increasing the chance of misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the skill supports other languages or that Chinese is a required locale for a region-specific use case. The policy explicitly calls for flagging language or locale constraints when they are imposed without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest states this skill is specifically for converting PDF files to Word (.docx), but the architecture explicitly includes LibreOffice for Office-to-Office and Office-to-PDF conversion, plus PDF-to-image and image-to-PDF tooling. That indicates a general document conversion service rather than a narrowly scoped PDF→Word skill.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The presence of a dedicated format route and a generic storage/conversion service, together with the data model's unconstrained 'format' and 'conversionType' fields, documents behavior broader than the manifest's single declared conversion type. This is a semantic mismatch between the skill's claimed purpose and the system it describes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a file conversion skill with status, download, batch conversion, and history, but the architecture adds JWT authentication plus login/register flows and a persistent User model. Those are product-platform capabilities that are not obviously required for the narrowly stated document-conversion skill itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.