kimi-pdf

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a PDF skill, but the required execution path relies on an unverified local wrapper script and a fix flow that likely installs additional tooling. Combined with external-search ingestion and runtime downloads by Playwright/Tectonic, this makes the skill high security risk despite no clear evidence of credential theft or confirmed malicious intent.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:53 AM
Package URL
pkg:socket/skills-sh/thvroyal%2Fkimi-skills%2Fkimi-pdf%2F@0f032bbd4256adfeb6ec46f8892db366458c0d28