ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      huyong2023

      Safety Report

      Pdf Smart Tool Cn

      @huyong2023

      PDF智能处理工具 v2.1 | PDF Smart Tool. 支持PDF转换、OCR识别、合并拆分、数字签名、批量处理、水印添加、加密解密。触发词:PDF、转换、识别。

      134Downloads
      1Installs
      0Stars
      2Versions
      PDF & Documents4,203

      Security Analysis

      medium confidence
      Suspicious

      The skill looks like a plausible PDF utility, but there are internal inconsistencies and unclear handling of sensitive artifacts (signing keys, certificates, outputs), so proceed with caution.

      Mar 5, 20262 files3 concerns
      Purpose & Capabilityconcern

      The skill claims local PDF/OCR/signature functionality which reasonably needs pdftotext, tesseract, and ghostscript (listed in SKILL.md metadata). However the registry-level requirements reported no required binaries or environment variables — this mismatch is an incoherence that could hide assumptions about available tooling or runtime behavior.

      Instruction Scopeconcern

      SKILL.md is an instruction-only spec describing user interactions and examples but is vague about implementation: it does not state where files are stored/processed, whether processing is local or uploaded to external services, nor how sensitive artifacts (private keys, enterprise seals, CA certificates) are supplied or protected. That open-endedness grants broad discretion to any runtime implementation and is a data-exfiltration risk if the agent chooses to upload files.

      Install Mechanismok

      No install spec and no code files are included (instruction-only). This minimizes disk-write/install risk. The SKILL.md does require certain binaries, but no installer is provided.

      Credentialsconcern

      No environment variables or credentials are declared, yet features like '数字证书 (CA digital certificate)' and '企业电子签章' imply access to sensitive private keys or enterprise credentials. The skill does not explain how those keys should be provided or protected, which is disproportionate and risky for handling sensitive secrets.

      Persistence & Privilegeok

      always is false and there is no install/persistence behavior in the package. The skill does not request to modify other skills or system-wide settings.

      Guidance

      This skill is plausibly a PDF tool but has gaps you should verify before installing: 1) Confirm where file processing happens — local on your machine or uploaded to a remote server. Avoid sending sensitive PDFs (contracts, IDs) until you know. 2) Ask the maintainer how private keys/certificates and enterprise seals are supplied and stored; never provide private keys unless you trust the implementation and transport/storage. 3) Resolve the metadata mismatch: SKILL.md lists required binaries (pdftotext, tesseract, ghostscript) but the registry entry shows none — ensure the runtime will have those trusted binaries installed from official sources. 4) Prefer testing with non-sensitive documents first. 5) If you need signing or enterprise features for production, require private deployment or clear documentation about endpoints, encryption, and credential handling. 6) If no homepage or author verification exists, treat this as higher risk and consider alternatives with clear source and installation instructions.

      Latest Release

      v1.1.0

      v1.1.0 brings major new features and enhancements: - 新增PDF转换(支持转Word/Excel/PPT/图片等多格式) - 新增OCR文字识别、多语言、表格与手写识别 - 增加PDF合并、拆分、页面提取等批量处理能力 - 支持数字签名(手写、电子签章、CA证书、时间戳) - 实现PDF加密解密、权限管理,水印添加与删除 - 增强批量操作能力,提升各功能全面性与易用性

      More by @huyong2023

      Smart Recruitment Cn

      0 stars

      Ai Contract Review Cn

      0 stars

      Ai Food Recommendation Cn

      0 stars

      Voice Note Transcriber Cn V1.1

      0 stars

      Smart Customer Service Cn Payment

      0 stars

      Ai Prompt Optimizer Cn V1.1

      0 stars

      Published by @huyong2023 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]