Back to skill

Security audit

Pdf Extract Hardened

Security checks for vulnerabilities and agentic risk

Overview

This is a narrow PDF text-extraction skill with clear local-only safeguards and no executable payloads bundled in the artifact.

Reasonable to install if you need local PDF-to-text extraction. Treat extracted PDF content as sensitive, avoid sending it to webhooks or shared logs, and only write extracted text to disk when you intentionally name an output file.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.