Back to skill

Security audit

OpenDataLoader PDF Parser (乌贼版)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward PDF conversion helper, with the main caution that parsed outputs may contain sensitive document content.

Before installing, confirm that `opendataloader-pdf` is the package you intend to trust. Use it only on PDFs you are allowed to process, choose output directories carefully, and review or sanitize extracted content before putting it into shared AI or RAG systems.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.