pandoc-convert

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Pandoc document-conversion helper with expected file conversion and optional installer behavior.

Before installing, be aware that conversions operate on the files or directories you provide and may overwrite output files. Review batch inputs and output directories, use --skip-existing when needed, and only approve the installer’s --yes mode after reviewing the printed package-manager command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
74% confidence
Finding
The skill description is very broad and could trigger on many ordinary document-related tasks, causing an agent to invoke a shell-capable conversion skill in situations where simpler or safer handling would suffice. Because the skill grants direct Bash and pandoc execution, overbroad routing increases the chance of unnecessary exposure to file-system access, command execution wrappers, and risky document-processing paths.

VirusTotal

57/57 vendors flagged this skill as clean.

View on VirusTotal