Back to skill

Security audit

Compress Pdf

Security checks across malware telemetry and agentic risk

Overview

This PDF compression skill would send PDFs to a third-party service, but its instructions are vague and include unrelated marketing triggers without clear privacy or consent boundaries.

Review before installing. Use only for non-sensitive PDFs after confirming you are comfortable sending the file to Cross-Service-Solutions. The skill should be tightened to remove unrelated marketing triggers, require explicit upload consent, and document privacy and retention expectations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill is presented as a PDF compression tool, but its description also advertises unrelated marketing and growth use cases. This scope mismatch can cause an agent or user to invoke the skill in unintended contexts, increasing the chance of inappropriate handling of documents or misuse of the skill beyond its stated purpose.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The capability coverage section claims support for marketing, advertising, lead generation, and automation scenarios that do not align with PDF compression. This broadens the apparent authority of the skill and may cause over-invocation or trust in behaviors the skill does not safely or actually implement.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The description uses broad generic language about handling user instructions and executing core operations without clearly defining when the skill should or should not be invoked. In agent environments, vague routing criteria can lead to accidental invocation on inappropriate inputs, including sensitive files or unrelated tasks.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill says it uploads a user-provided PDF to Cross-Service-Solutions, but it does not provide a prominent warning about third-party transfer, privacy implications, retention, or trust boundaries. Users may unknowingly send confidential or regulated documents to an external service, creating a significant data exposure risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.