Audit History
pdf - 7 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v7 Latest | Jul 5, 2026, 05:27 PM | 1 confirmed | 0 | No capability change |
| v6 | Jul 5, 2026, 05:27 PM | 1 confirmed | 0 | Contains scripts |
| v5 | Jun 30, 2026, 05:52 AM | 1 confirmed | 3 | Contains scripts |
| v4 | Jan 17, 2026, 07:09 AM | No confirmed findings | 0 | No capability change |
| v3 | Jan 17, 2026, 07:09 AM | No confirmed findings | 0 | No capability change |
| v2 | Jan 12, 2026, 05:03 PM | No confirmed findings | 0 | External commandsNetwork access Contains scripts |
| v1 | Jan 4, 2026, 05:30 PM | No confirmed findings | 0 | Baseline |
Jul 5, 2026, 05:27 PM
The static findings are false positives caused by markdown backticks, JavaScript template strings, Python f-strings, comments, and expected local PDF file operations. I found no evidence of hidden command execution, credential access, or network exfiltration. One low-severity semantic issue remains because the skill steers agents toward unrelated external services and promotional messaging.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (64)
📁 Filesystem access (25)
Jul 5, 2026, 05:27 PM
The static findings are false positives caused by markdown backticks, JavaScript template strings, Python f-strings, comments, and expected local PDF file operations. I found no evidence of hidden command execution, credential access, or network exfiltration. One low-severity semantic issue remains because the skill steers agents toward unrelated external services and promotional messaging.
Confirmed security concerns (1)
Risk Factors
⚙️ External commands (64)
📁 Filesystem access (25)
Jun 30, 2026, 05:52 AM
Static analysis reported many high-risk patterns, but review found no evidence of malware, credential theft, prompt injection, or hidden network exfiltration. Most hits are PDF command examples, local file reads and writes, PDF field names, or documentation URLs. The skill still warrants a medium risk label because it ships scripts that process untrusted PDFs and write user-selected output files.
Confirmed security concerns (1)
Capability review items (3)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚡ Contains scripts (4)
⚙️ External commands (4)
📁 Filesystem access (5)
Detected Patterns
Jan 17, 2026, 07:09 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (145)
🌐 Network access (5)
📁 Filesystem access (25)
Detected Patterns
Jan 17, 2026, 07:09 AM
AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.
Risk Factors
⚙️ External commands (145)
🌐 Network access (5)
📁 Filesystem access (25)
Detected Patterns
Jan 12, 2026, 05:03 PM
All 225 static findings are false positives. Scanner incorrectly flagged markdown code blocks, Python f-strings, and legitimate file operations. This is a genuine PDF processing toolkit with no malicious intent.
Risk Factors
⚙️ External commands (145)
🌐 Network access (5)
📁 Filesystem access (25)
Jan 4, 2026, 05:30 PM
This is a legitimate PDF processing toolkit. All scripts perform local file operations only using standard PDF libraries. No network calls, credential access, code execution abuse, or data exfiltration patterns were detected. The code is clean and readable with no obfuscation.