PDF to LaTeX

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward PDF-to-LaTeX helper, but documents processed through it may be handled by MinerU's external service.

Install only if you trust the MinerU CLI and provider. Protect your MINERU_TOKEN, consider pinning the CLI version, and avoid converting confidential, proprietary, unpublished, or regulated PDFs unless you are comfortable with MinerU processing the document contents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs users to submit local PDFs or remote URLs to the MinerU service and requires an API token, which strongly implies document contents are transmitted to an external service. Because the documentation does not clearly disclose that potentially sensitive document data leaves the local environment, users may unknowingly upload confidential papers, internal reports, or regulated data.

VirusTotal

48/48 vendors flagged this skill as clean.

View on VirusTotal