pdf2ofd

Security checks across malware telemetry and agentic risk

Overview

This is a local PDF-to-OFD converter whose file access matches its stated purpose, with ordinary dependency and document-handling cautions but no evidence of hidden or harmful behavior.

Use this skill only when you intend to convert a specific PDF to OFD, especially for sensitive invoices or reports. Install it in an isolated Python environment and pin current patched dependency versions before processing untrusted documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation guidance is broad enough to trigger on generic requests to convert a PDF, not just clearly authorized use of this specific tool. In an agent setting, overly broad triggers can cause the skill to activate on sensitive documents unexpectedly, increasing the chance of unintended file access, conversion of the wrong document, or unsafe autonomous action.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal