Nutrient PDF Plugin for OpenClaw
Security checks across malware telemetry and agentic risk
Overview
This plugin appears to be a straightforward local PDF-to-Markdown extractor, with the expected command execution needed to run the PDF conversion tool.
Install only if you want OpenClaw agents or the OpenClaw CLI to process local PDFs through Nutrient's pdf-to-markdown tool. Be aware that the plugin runs the configured PDF conversion command, including a startup --version probe, so avoid pointing its command setting at anything you do not trust and review the separate Nutrient licensing terms for higher-volume or commercial use.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
61/61 vendors flagged this plugin as clean.
