HTML Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a coherent MinerU HTML analysis helper, with normal third-party service and token-handling cautions.

Install only if you trust MinerU and the mineru-open-api package. Protect MINERU_TOKEN like any API credential, avoid placing it in shared files or logs, and do not submit confidential local HTML, internal URLs, or regulated content unless MinerU’s data handling is acceptable for that material.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises remote URL extraction and live crawling without warning that page content, URLs, and potentially sensitive query parameters or internal endpoints may be transmitted to an external MinerU service. In a security-sensitive agent environment, this can lead to unintended data disclosure or violation of network/data-handling expectations.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The documentation instructs users to configure MINERU_TOKEN but provides no guidance on protecting the credential, increasing the chance it will be hardcoded, logged, pasted into transcripts, or exposed in shell history. While this is not an active exploit path in the file itself, it materially raises the likelihood of credential mishandling.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal