borghei/pdf-toolkit
> Audit PDF files for metadata leakage, page count, encryption, JavaScript, embedded files, and version. Use before sending a PDF externally, when redacting sensitive metadata, or running a PDF security review.
npx skills add https://github.com/borghei/Claude-Skills --skill pdf-toolkit
Audit .pdf files for metadata, page count, encryption status, embedded JavaScript, embedded files, and PDF version — using the standard library only.
pdf, pdf audit, pdf metadata, pdf review, pdf leakage, pdf security, redaction, document handoff
Before running the audit, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
python scripts/pdf_auditor.py contract.pdf
Outputs: PDF version, page count, file size, metadata (Author, Title, Producer, Creator, dates), encryption status, embedded JavaScript indicators, embedded file indicators.
Goal: Stop leaking author identity, prior client names, or document history when handing a PDF to an external party.
Steps:
python scripts/pdf_auditor.py document.pdfAuthor matches the sender (not "Bob's intern" from a prior project)Title matches the document, not a leftover working titleProducer doesn't reveal an internal-only PDF toolCreationDate and ModDate are reasonable for the dealTime Estimate: 2-3 minutes per document.
Goal: Decide whether a received PDF can be opened safely on a managed laptop.
Steps:
Time Estimate: 1-2 minutes per inbound document.
Goal: Audit every PDF in a folder before zipping for a customer or partner.
Steps:
for f in *.pdf; do python scripts/pdf_auditor.py "$f" --json; done > audit.jsonlTime Estimate: 1-2 minutes per file.
Reads a PDF using stdlib parsing — no pypdf or pdfplumber required. Detects:
/Type /Page object scan)/Encrypt reference present)/JS, /JavaScript, /AA keys)/EmbeddedFiles)python scripts/pdf_auditor.py document.pdf
python scripts/pdf_auditor.py document.pdf --json
Limits:
pdfplumber or pypdf separately.references/pdf_handoff_guide.md — What to scrub from PDFs before external send; PDF/A and PDF/UA basics; common leakage patternsassets/pdf_handoff_checklist.md — Pre-send PDF sign-off checklistPublic-Report.pdf can carry private metadata indistinguishable to the human eye.legal/ for redacted contract handoffsc-level-advisor/board-deck-builder for board pack handoffmarketing/ for whitepaper / case-study handoffTake borghei/pdf-toolkit from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.