SecureSkill scanned pdf-smart-tool-cn by huyong2023 on 2026-04-21 using scanner version 0.1.0. Verdict: SAFE. Risk score: 1/10. No threats detected across 10 analysis layers. Platform: OpenClaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is 3c4ee31c-8c29-45bf-ae37-f98f9b83fadd.
This skill looks like a straightforward PDF helper description rather than an active program. It explains how PDF conversion, OCR, merging, signing, watermarking, and encryption are supposed to work, but it does not include any scripts or hooks that would actually run on your machine. I did not find any signs of data theft, hidden persistence, scanner evasion, or prompt manipulation. Based on the files provided, it is safe to treat this as low-risk documentation-only content.
Package Info
Permissions Requested
No findings — this skill passed all checks.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The package contains no scripts or hook handlers, so there is no direct code execution path on the user's machine.
There are no URLs, curl/wget commands, or other outbound communication mechanisms anywhere in the provided files.
The SKILL.md content is feature documentation and example dialogues for PDF tasks, not hidden instructions to read credentials, modify persistent agent files, or override system behavior.
Because this is a documentation-only skill with no executable components, the risk stays at the minimum baseline.
What to do
No threats detected across all 10 analysis layers
Monitor for future version changes that may introduce new capabilities
Scan ID
3c4ee31c
Scanner
v0.1.0
Date
Apr 21, 2026
Risk Score
1
Skill Version
1.1.0
Skill License
unspecified