killerpdf-portable-editor

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s functionality is coherent for a local PDF editor and there is no credential harvesting or exfiltration flow, but it instructs the agent/user to download and execute a prebuilt EXE from an external GitHub publisher that does not match the skill publisher, with no pinning or integrity verification. Building from source looks proportionate and lowers concern; the main risk is install trust, not malicious behavior.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 20, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fkillerpdf-portable-editor%2F@3c5da737c61f3ef254804ef82ff77f3cfdf3ac12