Back to skill

Security audit

my skill

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but converting untrusted Markdown through Pandoc and LaTeX can expose local files in the generated PDF if the input contains hostile raw TeX.

Install only if you will convert Markdown files you trust, or run it in a sandboxed environment with access limited to the input and output directories. Be especially careful before converting Markdown supplied by someone else and returning the generated PDF to them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/md2pdf.py:60
Finding

Untrusted Markdown Can Expose Local Files Through Raw TeX Processing

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: md2pdf
description: Convert Markdown files to PDF using Pandoc. Use when the user wants to export, convert, or generate a PDF from a .md file. Triggers: "convert md to pdf", "export pdf", "markdown to pdf", "generate pdf from markdown", "md to pdf", "导出PDF", "转成PDF", "markdown转pdf", "生成PDF".
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "export pdf" is broad enough to match requests unrelated to Markdown conversion, which can cause the wrong skill to activate and handle user input unexpectedly. In an agent ecosystem, ambiguous routing can lead to unintended file operations or user confusion, especially if another context was intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

These arguments hard-code SimSun, SimHei, Microsoft YaHei, and CJKmainfont values whenever the selected engine is XeLaTeX or LuaLaTeX. That imposes a specific locale/language-oriented rendering choice on all users instead of offering a configurable option or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The natural-language trigger list hard-codes support for specific languages/locales in the activation surface without documenting whether language selection is user-driven. Under the policy, locale or language behavior should be offered as a choice or clearly justified when constrained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file includes natural-language guidance favoring CJK support and later enforces Chinese font selections, which can be interpreted as a locale-specific default rather than a neutral, user-selectable setting. Because no opt-in or alternative locale behavior is described, this is a mild language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.