Doc OCR

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a coherent document OCR/extraction helper that uses MinerU, with a privacy caveat around sending documents to an external service.

Install only if you are comfortable using MinerU for document parsing. Avoid confidential, regulated, customer, or secret-bearing documents unless your organization permits sending that material to the provider and you understand its retention and privacy terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill documents token setup and use of a third-party CLI/API, but it does not clearly warn users in the main skill description or usage guidance that OCR may transmit document contents to an external MinerU service. For a document-processing skill, this omission can cause users to send sensitive legal, office, or archival material off-host without informed consent, creating confidentiality and compliance risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal