Back to skill

Security audit

Specification Extractor

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a straightforward tool for extracting structured information from construction specification PDFs, with no evidence of hidden or harmful behavior.

Install this only if you are comfortable letting it read the construction specification files you explicitly provide. Avoid pointing it at unrelated private documents, and review any exported CSV, Excel, JSON, or report output before sharing it.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.