Back to skill

Security audit

Pub Nanopdf

Security checks across malware telemetry and agentic risk

Overview

This skill is a broad external AI/API gateway packaged under a PDF-focused name, with email, SMS, scraping, and paid model access that deserve careful review before installation.

Install only if you intend to use a broad SkillBoss API integration, not just a PDF editor. Use a limited or test API key if possible, confirm billing and provider data-handling expectations, avoid sensitive documents unless approved, and require explicit user approval before any email, SMS, batch messaging, scraping, or costly model action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest and top-level description present this as a narrowly scoped PDF-editing skill, but the body exposes a general-purpose third-party API for chat, media generation, search, document parsing, email, and SMS. This scope mismatch is dangerous because users and orchestrators may grant trust, keys, or workflow access appropriate for PDF editing while unknowingly enabling unrelated outbound and real-world action capabilities.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Including email-sending in a skill framed as PDF editing materially expands its action surface into real-world outbound communication. That can enable spam, phishing, unauthorized notifications, or exfiltration of document contents through email under a misleading skill identity.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
SMS verification/OTP operations are unrelated to PDF editing and introduce real-world messaging capability that can be abused for unwanted texts, account workflows, or social engineering. The mismatch increases the chance that operators overlook the presence of telecom-integrated actions when approving the skill.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill exposes broad chat, image, video, audio, document, and web-search functionality despite being labeled as a PDF editor. This overbroad capability set violates least privilege and increases the risk of unexpected data exfiltration, misuse of the provided API key, and execution of workflows far outside user expectations.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file documents image-generation and image-processing models even though the skill is presented as focused on PDF editing. This kind of capability drift increases the effective attack surface, can mislead users and reviewers about what the skill can do, and may enable unreviewed data flows or policy violations through models unrelated to the declared purpose.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The file documents operational capabilities for email, SMS, embeddings, and presentation generation that significantly exceed the skill's stated purpose of PDF editing. This kind of scope expansion increases the chance of unintended tool exposure, user deception, and abuse of high-risk outbound actions such as sending emails or SMS messages if the surrounding skill wiring or authorization is permissive.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The description advertises email and SMS capabilities without warning that the skill can perform real-world outbound actions or process user data through external services. Users may invoke the skill believing it is passive document tooling when it can actually contact third parties and transmit sensitive content.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The examples encourage sending prompts, documents, and audio-derived content to an external API without any privacy or data-handling warning. In a document/PDF context, users may submit confidential files or sensitive text assuming local processing, creating avoidable confidentiality risk.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.