Back to skill

Security audit

PDF Extract

Security checks across malware telemetry and agentic risk

Overview

This skill uploads user-confirmed documents to ComPDF for disclosed PDF processing tasks and does not show hidden code, silent exfiltration, or automatic destructive behavior.

Install this only if you are comfortable sending selected documents, and possibly encrypted-PDF passwords, to ComPDF's cloud service. Review the requested operation carefully because the skill covers more than extraction, including conversion and PDF editing. Avoid using it for highly sensitive documents unless your ComPDF account, privacy requirements, and data-handling obligations allow that upload.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as an extraction-focused capability, but its documented behavior spans many broader document transformation and management actions. This scope mismatch can cause the agent to invoke the skill in contexts users did not expect, increasing the chance of unintended file uploads or document modification through a third-party API.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The tool-selection section advertises many non-extraction endpoints, including conversion and editing operations, despite the skill being framed as PDF extraction. That mismatch broadens the effective privilege and action surface of the skill, making accidental or inappropriate invocation more likely and reducing the user's ability to predict what the skill may do.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The documented parameter surface includes merge, split, delete, rotate, insert, watermark, compression, and comparison capabilities that materially exceed the skill's extraction-focused description. This creates a scope mismatch that can mislead users, agents, or policy layers into invoking document-modifying operations under an extraction-branded skill, increasing the chance of unauthorized or unsafe file manipulation.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The reference file exposes a much broader capability surface than the skill’s stated extraction-only purpose, including document conversion, editing, comparison, and generation operations. In an agent setting, this kind of overbroad tool disclosure can enable unintended tool selection or prompt-induced misuse, weakening least-privilege boundaries and creating opportunities for unauthorized document modification or exfiltration workflows.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documented inclusion of PDF modification and generation features is not justified by the extraction skill’s purpose and expands the reachable action set to state-changing operations. This is dangerous because an attacker or confused agent could pivot from passive document extraction into active content manipulation, watermark removal, file generation, or comparison tasks that may alter evidence, bypass workflow expectations, or process sensitive data in unintended ways.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation condition 'User mentions ComPDF, compdf, or related keywords' is overly broad and may trigger on ordinary discussion rather than a clear request to process documents. In an agent setting, broad triggers can lead to premature collection of API keys, consent prompts, or external-processing workflows when the user only intended to ask a question.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The page-deletion operation is destructive and irreversible from the user's perspective, yet the documentation presents it as a normal parameter set without any warning, confirmation requirement, or backup guidance. In an agent workflow, this omission can cause accidental data loss if a model or caller selects the operation based on ambiguous user intent or malformed instructions.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.