pdf-extractor

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The PDF extraction skill demonstrates coherent purpose-capability alignment: multi-backend PDF text extraction with OCR support, and concrete CLI/Python usage. The installation flow relies on standard tools (uv, pip) to install dependencies and optional GPU models, which is typical for such tooling but introduces supply-chain risk if sources aren’t verifiably trustworthy. Data flows are predominantly local (PDF → MD outputs) with no explicit external data exfiltration. Overall, the footprint is proportionate to the stated purpose, with some elevated risk from multi-backend dependency installation and large optional model assets. Treat as BENIGN with MEDIUM security risk due to install-time dependencies and potential unverifiable assets; monitor for strict source-pinning and checksum verification in real deployments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:42 AM
Package URL
pkg:socket/skills-sh/ahundt%2Fautorun%2Fpdf-extractor%2F@98abe3ad570810b42a66dc95df24dfbf124ec20a