paper-parser-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about installing a third-party paper-parsing CLI and sending selected PDFs to MinerU for conversion.

Use a virtual environment or container, confirm the intended PyPI package and version before installing, keep the MinerU token revocable and protected, and only submit PDFs you are allowed to share with MinerU.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest trigger list contains very broad terms like "paper," "search," "download," and "parse," which are common words likely to appear in many unrelated conversations. This can cause unintended invocation of the skill, leading agents to install or run third-party code and potentially transmit PDFs and metadata to the external MinerU service when the user did not specifically intend to use this tool.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal