Back to skill

Security audit

pdf

Security checks across malware telemetry and agentic risk

Overview

This PDF skill performs local, user-directed PDF processing and form filling without hidden network access, credential use, persistence, or automatic high-impact behavior.

Install only if you are comfortable letting the agent read and transform PDFs you provide. Treat generated PNGs, JSON field files, extracted text, and filled PDFs as sensitive when the source document contains personal, medical, financial, or legal information, and delete intermediates when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to extract, transform, and persist form contents into PNGs and JSON files that can contain sensitive personal or regulated data, but it provides no guidance on data minimization, secure storage, redaction, retention, or cleanup. This increases the chance that PII from forms is unnecessarily written to disk, copied into intermediate artifacts, or left behind in working directories where other tools or users could access it.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.