Back to skill

Security audit

ComPDF Toolkit

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed ComPDF document-processing helper; it uses a local API key and external document uploads in ways that fit its stated purpose and require user confirmation for sensitive actions.

Install only if you are comfortable using ComPDF as an external document-processing service. Confirm before uploading confidential, regulated, or password-protected documents, keep the local API key file private, and handle decrypted outputs as unprotected sensitive files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The reference materially expands the skill from general ComPDF document processing into AI/IDP parsing and extraction endpoints that can extract structured data from uploaded documents. That increases the skill’s effective capability surface beyond the manifest description, which can surprise integrators and enable unintended sensitive-data extraction workflows.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The document immediately instructs users to send files to third-party ComPDF endpoints but does not prominently warn that uploaded documents leave the local environment and may contain sensitive content. In a document-processing skill, this omission can lead to accidental disclosure of confidential PDFs, images, contracts, or IDs to an external service.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The decryption section explains how to remove PDF password protection but does not warn that the resulting file will no longer enforce the original confidentiality or permission controls. In a security-sensitive document workflow, that omission can encourage unsafe handling of decrypted outputs and accidental redistribution of unprotected documents.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.