pdf-lab

Warn

Audited by Socket on Aug 26, 2026

4 alerts found:

Anomalyx4
AnomalyLOW
ui/server/index.ts

No clear malicious behavior or supply-chain backdoor is present. The code implements a local PDF artifact UI/API, with no outbound network communication, command execution, dynamic code execution, credential theft, persistence, or destructive actions. Security concerns are moderate: unauthenticated local read/write endpoints, filesystem path disclosure, broad static serving, possible symlink escape in artifact resolution, and weak validation of temporary directories used for file promotion. These issues should be addressed if the service can be reached by untrusted users or if its configured directories contain sensitive data.

Confidence: 96%Severity: 58%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated PDF-tuning purpose, but its footprint is high-impact because it can autonomously rewrite local pipeline code, persist learned changes, and operate through composed skills. Install trust looks relatively normal, and there is no clear credential theft or external exfiltration, so this is not confirmed malware; the main issue is disproportionate self-modifying power for an agent skill.

Confidence: 83%Severity: 66%
AnomalyLOW
pdf_lab.py

No direct malicious behavior is demonstrated in the supplied fragment. The primary concern is unrestricted execution of all matching local Python files through compile() and exec(), creating a high-impact injection point if package contents are tampered with. Review every cli_parts/part*.py file and consider normal imports or integrity validation. The incomplete final call also makes the provided code invalid as written.

Confidence: 97%Severity: 55%
AnomalyLOW
lib/agentic.py

The fragment is a dynamic plugin loader. It executes local Python files from a package subdirectory with full module-global privileges. This is inherently risky if package contents or the directory are writable or untrusted, but the fragment itself contains no clear malicious payload or exfiltration behavior. The incomplete final call would cause a syntax error if literal.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:07 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fpdf-lab%2F@f2aa6e5ec7e003b6c5c6cbf90c80e39ba67e78da
Security Audit — socket — pdf-lab