Back to skill

Security audit

Pdf Report Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a disclosed Markdown-to-PDF conversion and does not show hidden data access, persistence, network retrieval, or destructive behavior.

Install this if you want local Markdown-to-PDF report generation and are comfortable with it running a Node/pdfkit script that reads your Markdown and writes a PDF. Check dependency and font paths for your machine, and provide an explicit title if you do not want the default Chinese report title and page labels.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares environment-variable usage (PDFKIT_PATH, OPENCLAW_WORKSPACE) and relies on external binaries, but does not constrain tool scope via explicit permissions or allowed-tools. In agent environments, missing scope declarations can allow broader-than-expected execution context and make review or sandboxing weaker.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and description present the skill as generally usable for Markdown-to-PDF conversion, yet the examples and embedded defaults force Chinese strings such as page labels and report titles. This is a natural-language locale policy issue because the skill imposes a specific language without user opt-in or a clearly documented region-specific limitation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill instructs callers to spawn a Node.js subprocess to perform conversion, which expands the trust boundary from simple document formatting to arbitrary external code execution. If the script path or working directory is tampered with, or if this pattern is reused carelessly, it can enable execution of unintended code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The header text defaults to the Chinese title '市场报告' when no title is provided, which imposes a specific language choice in user-facing output. The file also repeats this default elsewhere, indicating a built-in locale preference rather than a user-selected option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The footer text uses the Chinese string '第 ${pageNum} 页' for all generated PDFs, which forces a locale-specific output format. There is no visible option in this file to choose another language or opt in to Chinese localization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI path assigns '市场报告' as the default report title, which forces Chinese output for users who do not provide a title. This is a user-facing locale decision made without any opt-in or documented region-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The markdown workflow explicitly tells the agent to save a temp file and then delete it, but the skill description does not warn the user that it will create and remove files during execution. Because this affects user/workspace data, even if temporary, the behavior should be disclosed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.