Back to skill

Security audit

Nano Pdf Tool Free

Security checks across malware telemetry and agentic risk

Overview

This PDF helper skill is a simple Markdown instruction set whose file and command access matches its stated PDF processing purpose.

Install only if you are comfortable letting the agent read and write the PDFs you name and run local Python/PDF commands. Review any generated shell or pip command before execution, and keep outputs in a controlled working folder.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly declares write and exec capabilities but does not clearly warn users that it can modify files and execute commands. In an agent environment, this can lead to unintended file changes or shell execution from ordinary-looking PDF requests, increasing the risk of destructive actions or abuse if the skill is auto-invoked.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.