Doc To Text

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Word-to-text helper, with the main caution that it uses a third-party MinerU CLI and token-backed extraction may expose document contents to that service.

Install only if you trust MinerU/OpenDataLab and the mineru-open-api package source. Keep MINERU_TOKEN private, and avoid processing confidential, regulated, or customer documents unless you are comfortable with the provider's data-handling terms and any organizational approvals required.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly supports local files and URLs and relies on MinerU token-based extraction, but it does not clearly warn that document contents or remote URLs may be transmitted to an external service. This creates a real data exposure risk because users may process sensitive Word documents under the assumption that conversion is local-only.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal