pdf-to-text

Warn

Audited by Socket on Sep 28, 2026

1 alert found:

Security
SecurityMEDIUM
bin/pdf-to-text

This is a CDN-driven self-updater/installer whose primary security weakness is supply-chain trust: the script downloads and executes a platform-specific binary from a remote location with no cryptographic integrity/authenticity verification, and it extracts untrusted tar archives with minimal hardening and only superficial post-install validation. No explicit backdoor/exfiltration logic is visible in this wrapper, but if the CDN content or release artifact is tampered with, the executed payload would run directly under the user account. Strongly consider adding signature/checksum verification (and ideally hardened/tar-safe extraction plus stronger content validation) before executing downloaded binaries.

Confidence: 72%Severity: 76%
Audit Metadata
Analyzed At
Sep 28, 2026, 04:17 PM
Package URL
pkg:socket/skills-sh/pspdfkit-labs%2Fnutrient-skills%2Fpdf-to-text%2F@119024f025d49a3f5657d2621735573e0cc42d052ccb87490d5fdd77c2e10f34
Security Audit — socket — pdf-to-text