Back to skill

Security audit

PDF精简工具

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a PDF editing helper, but its instructions mix local PDF editing with unrelated workflow orchestration and external API language, so users should review it before installing.

Install only if you are comfortable with an agent running a PDF-editing CLI on your files. Use copies of PDFs, specify explicit output paths, avoid sensitive documents unless you know whether nano-pdf processes data locally or externally, and review any command before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The skill is presented as a PDF-editing tool, but this section describes workflow/DAG orchestration, conditional branches, and retries that do not match the advertised function. That mismatch can mislead an agent or user about the skill’s real behavior and expand trust beyond the documented scope, increasing the chance of unintended execution paths or misuse of exec-enabled capabilities.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill advertises external API/service integration even though it is framed as a local nano-pdf CLI editor. This inconsistency obscures the true trust boundary and may cause users or agents to provide data assuming local-only processing, when documents or metadata could be sent to external services.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description uses broad natural-language invocation framing without clear activation constraints, while the skill has read/exec/write capabilities. In that context, vague triggering language can cause over-broad activation and unsafe execution on user files or unintended documents.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documentation does not prominently warn that the skill modifies PDFs and may overwrite or alter user documents. Because the skill includes write and exec capabilities, missing upfront warnings increases the risk of destructive or irreversible changes, especially when users treat natural-language edits as low risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.