Back to skill

Security audit

Paper PDF Translation

Security checks across malware telemetry and agentic risk

Overview

The skill fits its PDF-translation purpose, but should be reviewed before install because its broad Pillow dependency can accept vulnerable image-processing versions.

Review before installing. Pin Pillow to a patched current version and run dependency scanning, install in a virtual environment, and be aware that Workspace/.work keeps source PDFs and intermediates while Zotero finalization changes Zotero attachments.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The contract states that, by default, all human-readable text must be converted into Simplified Chinese, while other target languages are only experimental and require extra validation. This can override or constrain user language choice, create silent language coercion, and cause the skill to rewrite source-visible content into a different language than intended, which is especially risky in academic translation workflows where fidelity, accessibility, and locale requirements matter.

Known Vulnerable Dependency: Pillow==10 — 10 advisory(ies): CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2024-28219 (Pillow buffer overflow vulnerability); CVE-2026-55379 (Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()`) +7 more

Critical
Category
Supply Chain
Confidence
88% confidence
Finding
Pillow==10

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.