Caveat verdict

Extract PDF Text

extract-pdf-text

88
๐ŸŸข Trusted
No high-risk patterns surfaced by the deep scan โ€” automated capability review, not behavioral proof.

Local PDF text extraction using PyMuPDF; file_read is for reading the target PDF and package_install is for pip install PyMuPDF, both matching the stated local extraction purpose with no network exfiltration.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

38
security
90
transparency
90
maintenance

Permission integrity

Performs file operations but does not declare file-accessing binaries

file_read

Installs packages at runtime โ€” transitive dependencies are not auditable

package_install

Findings (2)

Pattern match critical

Possible hardcoded credential

examples.md ยท code ยท password="secret123

Pattern match high

References sudo โ€” requests elevated privileges

ocr.md ยท code ยท sudo

Permissions & capabilities

Requires 1 system binary.

package_installfile_read

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API