T09 · Insecure Skill Coding Practices
- Location
scripts/md2pdf.py:60- Finding
Untrusted Markdown Can Expose Local Files Through Raw TeX Processing
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it says, but converting untrusted Markdown through Pandoc and LaTeX can expose local files in the generated PDF if the input contains hostile raw TeX.
Install only if you will convert Markdown files you trust, or run it in a sandboxed environment with access limited to the input and output directories. Be especially careful before converting Markdown supplied by someone else and returning the generated PDF to them.
scripts/md2pdf.py:60Untrusted Markdown Can Expose Local Files Through Raw TeX Processing
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
---
name: md2pdf
description: Convert Markdown files to PDF using Pandoc. Use when the user wants to export, convert, or generate a PDF from a .md file. Triggers: "convert md to pdf", "export pdf", "markdown to pdf", "generate pdf from markdown", "md to pdf", "导出PDF", "转成PDF", "markdown转pdf", "生成PDF".
---
The trigger phrase "export pdf" is broad enough to match requests unrelated to Markdown conversion, which can cause the wrong skill to activate and handle user input unexpectedly. In an agent ecosystem, ambiguous routing can lead to unintended file operations or user confusion, especially if another context was intended.
These arguments hard-code SimSun, SimHei, Microsoft YaHei, and CJKmainfont values whenever the selected engine is XeLaTeX or LuaLaTeX. That imposes a specific locale/language-oriented rendering choice on all users instead of offering a configurable option or documenting a justified regional constraint.
The natural-language trigger list hard-codes support for specific languages/locales in the activation surface without documenting whether language selection is user-driven. Under the policy, locale or language behavior should be offered as a choice or clearly justified when constrained.
The file includes natural-language guidance favoring CJK support and later enforces Chinese font selections, which can be interpreted as a locale-specific default rather than a neutral, user-selectable setting. Because no opt-in or alternative locale behavior is described, this is a mild language/locale policy concern.
No suspicious patterns detected.