Trusted — Risk Score 5/100
Last scan:2 days ago Rescan
5 /100
pdf-analysis
Analyze the structure, layout, and content of PDF documents using MinerU
Pure documentation skill that describes a legitimate third-party PDF analysis CLI (MinerU) with no executable code, no hidden functionality, and no security violations.
Skill Namepdf-analysis
Duration26.3s
Enginepi
Safe to install
No action needed. This skill is a documentation-only wrapper for a known open-source PDF analysis tool.
ResourceDeclaredInferredStatusEvidence
Filesystem NONE NONE No file operations in skill - only documents CLI output options
Network NONE NONE Skill documents remote URL input but makes no direct network calls itself
Shell NONE NONE No shell execution in skill - only documents CLI commands for user reference
Environment NONE NONE Documents MINERU_TOKEN env var but does not access it
2 findings
🔗
Medium External URL 外部 URL
https://mineru.net
SKILL.md:4
🔗
Medium External URL 外部 URL
https://mineru.net/apiManage/token
SKILL.md:48

File Tree

1 files · 3.3 KB · 63 lines
Markdown 1f · 63L
└─ 📝 SKILL.md Markdown 63L · 3.3 KB

Security Positives

✓ No executable code present - skill is documentation-only (SKILL.md)
✓ No hidden functionality or undocumented behavior
✓ References legitimate open-source project (MinerU by OpenDataLab/Shanghai AI Lab)
✓ No credential harvesting, data exfiltration, or suspicious API calls
✓ Full transparency about external service dependencies and token requirements
✓ No base64, eval, or obfuscated code patterns
✓ No access to sensitive paths (~/.ssh, ~/.aws, .env)