Back to skill

Security audit

pdf

Security checks across malware telemetry and agentic risk

Overview

This is a local PDF-processing guide; its risky examples are ordinary PDF operations but users should handle decrypted or modified documents carefully.

Install/use this only for PDFs you are authorized to process. Work in a private folder, keep backups before repair or modification commands, review outputs before sharing, and delete temporary images, JSON files, text extracts, and decrypted copies that contain sensitive information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The guide explicitly includes a qpdf example for decrypting a password-protected PDF without any surrounding warning that this should only be done for documents the user is authorized to access. In an agent skill, this can normalize or operationalize bypassing document protections, increasing the chance an automated system assists with unauthorized access to protected content.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.