Back to skill

Security audit

Pdf Tool

Security checks for vulnerabilities and agentic risk

Overview

This is a local PDF utility with no hidden networking or persistence, though some advertised PDF features are not actually implemented.

Use it only on PDFs you intend to process locally, install pypdf from a trusted source, and avoid output paths that could overwrite important files. Treat this version as a basic merge, split, page extraction, text extraction, and metadata tool until the advertised image, conversion, and compression features are added and reviewed.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.