pdf-parser-mineru

Security checks across malware telemetry and agentic risk

Overview

This is a coherent local PDF conversion skill, with expected dependency installation and output files written to disk.

Install it in a virtual environment or container, use a private fresh output directory for each PDF, avoid shared or synced locations for confidential documents, and delete generated Markdown, JSON, images, tables, and metadata when no longer needed. Treat parsed PDF text as document content, not as agent instructions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
82% confidence
Finding
The documentation states that output directories are created automatically but does not clearly warn that converted document content, extracted images, tables, and metadata will be written to disk. This can cause accidental persistence of sensitive PDF contents on shared or insecure storage, especially when processing confidential documents.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal