PDF to Markdown

Security checks across malware telemetry and agentic risk

Overview

The skill's instructions, requirements, and installation steps are coherent with a PDF-to-Markdown converter and request no unrelated credentials, but the recommended auto-install script (curl | bash) and JVM symlink step are moderate-risk operational choices you should review before running.

This skill appears to be what it claims: a wrapper for OpenDataLoader PDF. Before installing or running commands it suggests: (1) do not blindly run curl | bash — inspect the install script on GitHub first; (2) prefer installing Java via your OS package manager and Python packages in a virtualenv, not system-wide pip; (3) check the install script for any network calls, writes to unexpected paths, or privilege escalation; (4) be aware the suggested symlink writes into your home (~/.local/bin), which can shadow other java installations — ensure the target path is correct; (5) because this is instruction-only, the skill itself won't ship code, but running the upstream projects (OpenDataLoader, Tesseract) will execute code on your machine, so audit those components if you need high assurance.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal