Known Vulnerable Dependency: pymupdf — 2 advisory(ies): CVE-2026-3029 (PyMuPDF has a path traversal in _main_.py); CVE-2026-3029 (PyMuPDF has a path traversal in _main_.py)
Medium
- Category
- Supply Chain
- Confidence
- 94% confidence
- Finding
- pymupdf
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward local PDF extraction tool, with dependency hygiene notes but no hidden or purpose-mismatched behavior found.
Install this only in an environment where PDF parsing risk is acceptable. For sensitive or hostile PDFs, use an isolated environment and ensure dependency resolution selects patched versions of PyMuPDF and Pillow rather than old vulnerable releases.
64/64 vendors flagged this skill as clean.
No suspicious patterns detected.