Back to skill

Security audit

AI-powered PDF organizer with smart naming

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PDF organizer, but users should treat processed PDFs and API keys as sensitive because it relies on external AI APIs.

Install only if you are comfortable sending excerpts of your PDFs to the selected AI provider. Use dry_run first, keep input_folder narrow, avoid regulated or confidential PDFs unless your provider settings allow it, and store API keys outside shared repositories or rotate them if exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

API Key Stored in Plaintext Configuration File

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–22
Vulnerability Type: Plaintext secret storage in local configuration
Risk Level: Medium

Vulnerable Code Snippet

markdown
## Usage
1. Configure API key in `config.json`
2. Place PDF files in `input_pdfs/` folder

Line 39 further defines the configuration value:

markdown
- `openai_api_key`: Your API key (required)

Technical Analysis

The documented setup directs users to place an OpenAI or Kimi API key in config.json. It does not prescribe environment variables, an operating-system credential store, restrictive file permissions, source-control exclusions, or another secret-management mechanism.

A plaintext configuration file can be unintentionally committed to source control, included in backups or diagnostic archives, copied during project sharing, or read by another account with local file access. The implementation files are absent from the audited artifact, so whether any undocumented protections exist cannot be verified.

Attack Path

  1. A user follows the documented setup and writes a valid API key into config.json.
  2. The configuration file is committed to a repository, included in a backup or support archive, or exposed to another local user.
  3. An attacker extracts the plaintext key.
  4. The attacker submits requests to the corresponding API under the victim's account.
  5. The key remains usable until it is revoked or restricted by the provider.

Impact Assessment

Exploitation grants the attacker the API permissions assigned to the exposed key. Potential impact includes unauthorized model usage, financial charges, consumption of quotas, access to provider resources available to that credential, and account abuse attributable to the victim. This finding does not establish operating-system privilege escalation.

Remediation
View remediation

Remediation Suggestions

  • Read API credentials from environment variables or a supported secret manager rather than config.json.
  • Provide a sanitized config.example.json containing placeholders only.
  • Add config.json and other credential-bearing files to .gitignore.
  • Validate at startup that placeholder or empty credentials are rejected without printing the key.
  • Ensure logs and error messages redact API keys.
  • Document restrictive local permissions, such as owner-only read/write access.
  • Recommend provider-side restrictions, usage limits, monitoring, and periodic rotation.
  • If a key has previously been committed, revoke and rotate it; deleting it only from the latest revision does not remove it from repository history.

other

Warning
Location
SKILL.md:5
Finding

Potential Disclosure of PDF Content to External AI Providers

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 5
Vulnerability Type: Undisclosed third-party data transmission
Risk Level: Medium

Vulnerable Code Snippet

markdown
- **AI-Powered Content Analysis**: Uses OpenAI/Kimi API to extract titles, authors, and journal names

The amount of content sent for analysis is also configurable at line 46:

markdown
- `max_chars`: Maximum characters to analyze from each PDF

Technical Analysis

The documented workflow uses OpenAI or Kimi to analyze PDF-derived content. This implies that some portion of each document is transmitted to an external service. The documentation does not warn users about this data flow or describe consent, redaction, transport safeguards, provider retention, regional processing, contractual controls, or a local-only alternative.

PDFs may contain confidential business information, personal data, intellectual property, credentials, legal material, health information, or other regulated content. Although max_chars may limit the transmitted volume, limiting character count does not ensure that sensitive information is excluded. The implementation is absent, so the exact payload, endpoint validation, transport behavior, and retention controls cannot be verified.

Attack Path

  1. A user places a sensitive PDF in input_pdfs/ as instructed.
  2. The organizer extracts text from the PDF.
  3. The configured portion of the extracted content is submitted to OpenAI or Kimi for analysis.
  4. The external provider processes—and may retain or log—the submitted content according to its service configuration and policies.
  5. Sensitive information consequently leaves the user's local trust boundary without an explicit warning or document-level approval step.

This exposure follows the documented workflow and does not require an attacker to gain local code-execution privileges. Subsequent compromise, misuse, unintended retention, or ...[truncated 482 chars]

Remediation
View remediation

Remediation Suggestions

  • Clearly disclose that PDF-derived data is transmitted to the selected external provider before processing begins.
  • Require explicit user consent and provide a per-document confirmation option for sensitive files.
  • Minimize submitted data to the smallest excerpt necessary; prefer locally extracted metadata where possible.
  • Add configurable redaction for personal data, credentials, and other sensitive patterns.
  • Provide a fully local analysis mode for confidential or regulated documents.
  • Document provider endpoints, retention behavior, regional processing, and relevant privacy controls.
  • Use authenticated HTTPS endpoints and validate that provider base URLs cannot be redirected to untrusted destinations.
  • Avoid logging request bodies or extracted document text.
  • Support allowlists, sensitivity labels, and policy-based exclusion of protected documents.
  • Explain that max_chars limits volume but is not a confidentiality control.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states it uses OpenAI/Kimi APIs to analyze PDF content, but the description does not clearly warn users that document text may be transmitted to third-party services. This creates a real privacy and data-handling risk because users may process sensitive PDFs under the assumption analysis is local, leading to unintended disclosure of confidential information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.