Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

PDF助手

提供PDF转换、合并、拆分、压缩和编辑等功能,支持多种文档和图片格式互转处理。

MIT-0 · Free to use, modify, and redistribute. No attribution required.
0 · 192 · 1 current installs · 1 all-time installs
MIT-0
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The description (PDF convert/merge/split/etc.) matches the instructions that say files are submitted to a processing platform (TinyWow). However, the SKILL.md also includes an inline 'SkillPay.me' API key and pricing information even though the skill declares no required credentials or payment integration — embedding a payment/API key in the README without declaring it or explaining its use is inconsistent with the skill metadata.
!
Instruction Scope
The runtime instructions are very high-level: they expect the agent to accept user file uploads and 'submit' them to an external processing platform (TinyWow). No concrete endpoints, API calls, or explicit consent/handling rules are provided. That vagueness gives the agent broad discretion to transmit user files externally (including potentially sensitive data) and does not explain how or where payments are processed.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing will be written to disk or installed during skill setup — low install-surface risk.
!
Credentials
The skill declares no required environment variables or credentials, yet SKILL.md contains a hard-coded API key for 'SkillPay.me'. That embedded secret is unexpected and unexplained; credentials should be declared in metadata and not baked into instructions. Also, there is no justification for why a payment API key is needed to perform PDF processing via TinyWow.
Persistence & Privilege
The skill does not request always:true and has no special OS or config-path requirements. Autonomous invocation is allowed (platform default), which is normal — there are no elevated persistence or cross-skill configuration changes requested.
What to consider before installing
Before installing, consider these points: - The skill will (per its text) upload user files to an external service (TinyWow). If those files contain sensitive data, you should not send them to a third-party service without certainty about retention and privacy practices. The README claims 24-hour deletion but provides no guarantee or audit details. - The SKILL.md embeds a raw API key for 'SkillPay.me' and pricing info. The skill metadata declares no required credentials, so this is inconsistent. Embedded keys in documentation can be leaked credentials, placeholders, or an attempt to hard-code payment access — ask the author to explain why this key is present, remove it from public docs, and provide a way to set any required keys via environment variables instead. - The instructions are vague about exact API endpoints and how payment is handled. Ask for: (a) concrete API call examples showing where files are sent, (b) a privacy/data-retention statement from the processing provider, and (c) clarification about the payment flow (who is charged and how the embedded key is used). - If you plan to process sensitive documents, prefer a skill that documents explicit endpoints, requires credentials via secure environment variables (not embedded in SKILL.md), or runs locally without sending files to a third party. What would change this assessment: if the author confirms the SkillPay key is a harmless placeholder (and removes it), provides exact API call details and a privacy/retention policy from TinyWow, or updates the skill to require a user-provided payment credential (declared in metadata) instead of embedding a key. Without that, treat this skill cautiously and avoid uploading sensitive files.

Like a lobster shell, security has layers — review code before you run it.

Current versionv1.0.0
Download zip
latestvk9768v4fj9y3j2w68ha5q1fh5d82gavd

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

SKILL.md

PDF助手 - 文件处理工具

简介

PDF助手 - 专业的PDF文件处理工具,支持PDF创建、转换、合并、拆分等功能。

功能

  1. PDF转换 - PDF转Word、Excel、PPT、图片等
  2. 文件转PDF - Word/Excel/PPT/图片转PDF
  3. PDF合并 - 多个PDF文件合并为一个
  4. PDF拆分 - 将PDF拆分为多个文件
  5. PDF压缩 - 压缩PDF文件大小
  6. PDF编辑 - PDF旋转、裁剪、提取页面等

定价

  • 费用: 0.001 USDT / 每次调用
  • 支付方式: SkillPay.me
  • API Key: sk_3bf4e74479614724623768f5269c68251b09adf555a891eda68dbdfeac108f01

使用方法

转换功能

把 这个PDF转成Word
把这个Word文件转成PDF
把图片转成PDF

合并功能

合并这几个PDF文件
把file1.pdf和file2.pdf合并

拆分功能

拆分这个PDF
把PDF每页拆分成单独文件

其他

压缩这个PDF
旋转PDF的页面
提取PDF的指定页面

支持的格式

输入格式:

  • PDF, DOC, DOCX, XLS, XLSX, PPT, PPTX
  • JPG, JPEG, PNG, GIF, BMP, WEBP
  • TXT, HTML

输出格式:

  • PDF, DOC, DOCX, XLS, XLSX, PPT, PPTX
  • JPG, PNG, WEBP
  • TXT, HTML

处理流程

  1. 用户上传需要处理的文件
  2. 系统将文件提交至处理平台
  3. 完成处理后返回结果文件给用户
  4. 所有文件处理完成后自动清理,保护隐私

注意事项

  • 单个文件大小限制:10MB
  • 每次最多处理5个文件
  • 处理时间根据文件大小和网络情况可能需要等待
  • 所有上传文件会在24小时后自动删除

数据来源

使用 TinyWow 进行文件处理 - 免费在线文件处理工具。

版本

  • v1.0.0 - 初始版本

Files

1 total
Select a file
Select a file to preview.

Comments

Loading comments…