Back to skill

Security audit

ComPDF Documents To PDF

Security checks across malware telemetry and agentic risk

Overview

The skill has a legitimate ComPDF document-to-PDF purpose, but it bundles broad unrelated API documentation such as decryption, PDF editing, and AI extraction that users should review before installing.

Install only if you are comfortable with a cloud ComPDF workflow that reads a local API key and uploads documents for processing. The main instructions limit use to document-to-PDF conversion, but the package includes broad unrelated API references; users or admins should verify agents are constrained to the listed conversion-to-PDF endpoints before using it with sensitive files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill claims a narrow document-to-PDF purpose, but the content also references refreshing a broad local API snapshot and handling many unrelated API areas through external documentation files. This mismatch increases the risk that an agent will access broader network/file functionality than the user intended, potentially selecting unsafe or out-of-scope endpoints or processing sensitive documents with external services without clear user awareness.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The endpoint index advertises many capabilities outside the skill’s declared purpose of converting documents and images into PDF, including PDF-to-other-format, AI extraction/parsing, document comparison, encryption/decryption, and page-manipulation operations. This creates a scope mismatch that can enable unintended tool use by an agent or downstream orchestrator, increasing the chance of unauthorized data transformation or exfiltration through endpoints the user did not reasonably expect this skill to expose.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The reference file materially exceeds the skill's stated purpose of converting documents and images to PDF by documenting decryption, encryption, editing, extraction, AI parsing, and other unrelated capabilities. In an agent setting, broad undocumented capability surface increases the chance the skill or downstream tooling is invoked for unsafe or unauthorized actions beyond user expectations.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Including PDF decryption in a document-to-PDF skill exposes a capability that can remove protections from user-supplied documents, which is far outside the stated function. In this context, such a mismatch is dangerous because an agent could be prompted to perform unauthorized access-enabling actions under the guise of normal document conversion.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Encryption and permission-control features are outside the declared scope of a simple documents-to-PDF converter, creating hidden capability expansion. While encryption is not inherently malicious, exposing it through this skill can bypass user expectations and lead to misuse, especially if an agent autonomously selects available operations from bundled references.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
AI parsing and extraction APIs can pull structured data from documents, which is a substantially different and more privacy-sensitive capability than converting files to PDF. In a conversion skill, this creates risk of silent data extraction from uploaded files and widens the attack surface for prompt-driven misuse.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
PDF editing and manipulation operations such as merge, split, delete, extract, insert, and rotate are broader than the skill's promised conversion behavior. This mismatch can cause an agent or maintainer to treat the skill as a general document operator, increasing the chance of unintended destructive or privacy-impacting actions.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The script snapshots a very broad set of ComPDF documentation pages, including unrelated PDF manipulation and AI extraction/parsing APIs, rather than only the document-to-PDF capabilities declared by the skill. This creates a capability/intent mismatch: support materials may expose or normalize use of endpoints outside the stated scope, increasing the chance the agent is later extended or prompted into performing unintended actions.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file purpose and collected references cover capabilities far broader than 'documents to PDF', including PDF-to-other-format conversions, document extraction, comparison, encryption/decryption, and AI features. In an agent skill, overbroad reference material is dangerous because it can silently widen the effective operational knowledge available to the system and undermine least-privilege expectations set by the skill metadata.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The workflow documents direct upload of user files to a third-party API and retrieval via returned download URLs without any warning about external data transfer, retention window, or trust boundary change. For a document-processing skill, omission of this disclosure is security-relevant because users may upload sensitive business files assuming local-only handling.

Missing User Warnings

Low
Confidence
74% confidence
Finding
The webhook section explains pushing task events to callback endpoints but does not warn that task IDs, file-related metadata, and timing information will be sent to user-specified URLs. This is a smaller issue than raw file exposure, but it still creates metadata leakage and SSRF-adjacent integration risk if callback targets are insufficiently controlled.

Ssd 3

Medium
Confidence
99% confidence
Finding
The encryption response example includes plaintext password material inside fileParameter, demonstrating or normalizing unsafe secret handling in returned metadata. If mirrored in real integrations, logs, traces, clients, and analytics systems could retain document passwords, enabling later unauthorized access.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.