Back to skill

Security audit

Doc To Markdown

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward Word-to-Markdown helper, but users should remember that document conversion may involve a third-party MinerU service.

Install only if you trust the MinerU CLI and service. Avoid processing confidential Word documents or private URLs unless you are comfortable with that content being handled by MinerU/OpenDataLab, and use a revocable MINERU_TOKEN where possible.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly supports local files and URLs and relies on an external service/API, but it does not clearly disclose that document contents may be transmitted off-host for processing. Users may provide sensitive Word documents under the assumption of local-only handling, creating a real privacy and data exposure risk, especially for confidential business or personal files.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.