mineru

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md documents legitimate usage of the MinerU document-parsing API. The capability and required inputs (file URLs or uploads, an API key) align with the stated purpose. Network flows route to mineru.net and to presigned storage URLs, which is expected for a cloud parsing service but requires user trust in the provider for confidentiality. There are no signs of obfuscation, hidden download-and-execute patterns, credential forwarding to unknown third parties, or instructions that would enable autonomous harmful actions. The primary risk is data exposure to the remote service (sensitive documents uploaded) and standard API-key management risks. Overall: benign but standard privacy/trust considerations apply.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fmineru%2F@67a97070b66778f4ae0512982c5c36c795bfe4d6