nano-pdf

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose and usage are not consistent with the actual upstream package: it appears to describe a local PDF page-manipulation CLI, but the referenced package is a cloud-backed AI PDF editor requiring a Gemini API key and sending content to Google services. The install source is a normal PyPI package, so this is not confirmed malware, but the capability mismatch, omitted credential requirement, and undisclosed remote data flow make the skill internally inconsistent and risky.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Apr 7, 2026, 01:23 AM
Package URL
pkg:socket/skills-sh/wentorai%2FResearch-Claw%2Fnano-pdf%2F@d67b00f0481a8628058a2968235e237cc1dfb7c1