Back to skill

Security audit

Formula Ocr

Security checks across malware telemetry and agentic risk

Overview

This is a coherent MinerU formula OCR helper, but files or URLs processed with it should be treated as data shared with an external service.

Install only if you trust the MinerU CLI and service. Use a dedicated MinerU token where possible, do not process confidential documents or private/internal URLs unless MinerU's data handling is acceptable, and review outputs before relying on extracted formulas.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as formula OCR for PDFs and images, but the documentation expands scope to remote URLs and references a crawl capability. This creates a capability mismatch that can cause agents or users to send external resources to a third-party service unexpectedly, increasing SSRF-like data exposure, privacy, and unintended network access risks.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Advertising website crawling in a skill whose stated purpose is OCR of formulas from files/images introduces unnecessary network-retrieval behavior beyond user expectations. That broadened behavior can be abused to fetch unintended remote content, expose internal URLs if an agent passes them through, or trigger data handling that users did not consent to.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The documentation does not clearly warn that local files or supplied URLs may be transmitted to MinerU and that use requires an API token tied to an external service. This is a meaningful transparency and privacy issue because users may provide sensitive PDFs, images, or links without realizing their data leaves the local environment.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.