MinerU PDF Parser

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward MinerU API instruction skill, but documents and API tokens used with it are sent to MinerU’s external service.

Use this skill only for documents you are allowed to send to MinerU for cloud processing. Avoid confidential, regulated, or proprietary files unless you have approval and have reviewed MinerU’s privacy and retention terms, and protect MINERU_TOKEN like any other API key.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs users to submit document URLs, upload files via presigned URLs, and process them through a third-party MinerU service, but it does not warn that potentially sensitive documents will leave the local environment. This creates a real privacy and data-governance risk because users may unknowingly transmit confidential papers, internal documents, or regulated data to an external processor.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal