PDF Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a coherent PDF extraction helper, with the main privacy caution that selected PDFs or PDF URLs may be processed by MinerU.

Install only if you trust the MinerU CLI and are comfortable using it on the PDFs you choose. Avoid confidential, regulated, or internal-only documents unless your organization approves MinerU processing and you understand where document contents, URLs, and outputs may be sent or stored.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
85% confidence
Finding
The manifest description contains very broad trigger phrases like 'analyze a PDF document' and 'what is inside this PDF,' which can cause the skill to be invoked for many generic PDF-related requests without clear boundaries. Because this skill may process local files or fetch remote PDFs via an external service, over-broad activation increases the chance of unnecessary data exposure or use in contexts where the user did not intend third-party processing.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The documentation does not clearly warn that PDF contents and URLs may be transmitted to an external MinerU service, especially for URL inputs and token-backed extraction. Users could unknowingly send sensitive documents, internal URLs, or regulated data to a third party, creating privacy, confidentiality, and compliance risks.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal