password-protect-pdf
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill's footprint is largely coherent with its stated purpose: it offloads password-protection to a remote API and returns a download URL. However, there are notable privacy and trust concerns due to: (1) transmission of sensitive data (PDF and password) to an external service without explicit data handling details, (2) a suspicious-looking API domain, and (3) no explicit data retention/deletion policy. The credential handling (Bearer API key) is standard but requires secure storage and non-logging assurances. Overall, the design is plausible for a legitimate service but should be treated as suspicious until domain legitimacy, data retention policies, and consent disclosures are confirmed.
Confidence: 98%
Audit Metadata