Back to skill

Security audit

pdf-skill

Security checks for vulnerabilities and agentic risk

Overview

This PDF skill is a straightforward document-processing guide; its file access and PDF-writing examples fit the stated purpose, though users should run examples carefully to avoid overwriting files.

Install only the PDF/OCR packages you need, preferably in a virtual environment with reviewed pinned versions. Before running examples, change input and output paths to explicit safe filenames, avoid running them in directories with important PDFs, and escape or validate any untrusted data used to generate HTML-based PDFs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:19
Finding

Unpinned Third-Party Dependencies Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:502
Finding

Unescaped Report Data Is Interpolated into HTML Before PDF Rendering

Content
View full analysis
{product['name']} {product['units']} ${product['revenue']:,.2f} """ html += """ """ HTML(string=html).write_pdf(output_file) ``` ### Technical Analysis The report generator inserts `product['name']` directly into an HTML document without HTML escaping or contextual validation. The resulting string is then parsed by WeasyPrint as active HTML rather than treated exclusively as text. An attacker who controls a product name can terminate or restructure the surrounding table markup and insert arbitrary HTML or CSS. At minimum, this allows modification of the visual content and structure of the generated report. Depending on the WeasyPrint URL-fetcher configuration and runtime environment, injected resource elements or CSS URLs may also cause the renderer to request attacker-selected network resources or attempt to access local resources. The numeric formatting applied to `product['revenue']` limits straightforward markup injection through that field, but no equivalent protection is applied to `product['name']`. ### Attack Path 1. An attacker gains control over a product name supplied in the `data['products']` collection. 2. The attacker supplies a value containing crafted HTML, such as markup that closes the current table cell and inserts forged report content or external resource references. 3. `generate_report` concatenates that value directly into the HTML document. 4. `HTML(string=html).write_pdf(output_file)` parses the injected value as markup. 5. The generated PDF contains attacker-controlled content. If resource fetching is permitted, the renderer may also initiate requests to attacker- ...[truncated 845 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill contains many copy-pastable examples that create, overwrite, merge, split, encrypt, and delete local files without prominent safety warnings or guidance to use safe output paths. In an agent-skill context, a model may operationalize these examples on real user files or in the current working directory, causing unintended data modification, overwrite, or deletion even though the code is presented as documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.