Install
$ agentstack add skill-tiga001-captain-who-pdf ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Use only run_command for PDF processing; use read_image for visual inspection. The complete executable set is exactly pdfinfo, pdftotext, pdftoppm, python, python3, and rg. Commands such as head, tail, grep, sed, and awk are unavailable; never install replacements or fall back to system tools.
This Skill must be activated in the current Run. For its recognized managed PDF commands, omit run_command.cwd, including when no workspace is selected: the Host supplies a private working directory. This exception does not apply to ordinary shell commands. Omit runtimeProfile as well; the activated Skill binds the managed PDF runtime automatically. Do not guess a runtime profile, package version, executable path, or private directory. The binding grants no additional command, read, or write permission and never falls back to PATH.
For a PDF attachment, use attachments_list for this conversation or attachments_list_project for authorized project/task-tree attachments. Copy its exact returned readPath into a run_command.inputs item as path, with an optional safe relative mountPath (defaulting to the source filename). In the command, use $MYCOPILOT_INPUT_ROOT/; never treat the virtual attachment path as a workspace or private filesystem path.
For a PDF already in the selected workspace, use its exact safe workspace-relative path. This includes the exact workspace-relative PDF readPath returned by office_document.render for a QA PDF outside top-level outputs/: pass it unchanged, without run_command.inputs or a MYCOPILOT_INPUT_ROOT rewrite. For an attachment, external file, generated Artifact, Skill resource, script, image, font, or other source, keep using run_command.inputs, then use its mounted path below MYCOPILOT_INPUT_ROOT. Never guess a physical attachment, Artifact, runtime, or private working-directory path.
Reserve the managed PDF command's top-level outputs/ directory for files that command creates, such as page images. Never use outputs/ as an input alias or reconstruct an input path there; use the exact source path instead.
Core workflow
- Run
pdfinfoto learn page count, encryption state, page size, and relevant metadata. - For a large text PDF, locate a section with bounded streaming search before extracting pages:
``sh pdftotext -layout "manual.pdf" - | rg -n -i -C 4 --max-count 20 "steady|unit operation" ``
To inspect only the first N extracted lines, use the receipt-bound rg instead of head:
``sh pdftotext -layout "manual.pdf" - | rg --max-count 80 '^' ``
- Extract only the matching page range plus necessary adjacent pages with
pdftotext -f FIRST -l LAST. Userg --max-count Nto bound matches or initial lines. Do not print an entire large PDF, repeatedly slice the same full extraction by output offsets, or rerun a command whose archived result is available throughhistoryOpen; open that exact result withconversation_historyinstead. - Use text extraction for meaning, not visual proof. Render relevant pages for scans, tables, figures, columns, forms, or layout questions. Copy each returned image
readPathunchanged intoread_image.path, using only the reader actually provided in the current model request; do not reconstruct image paths from filenames or request arguments. If image reading is unavailable, report the missing visual coverage. If text is empty or damaged, switch to page rendering. - After creating or editing, reopen the PDF, validate its structure and requested content, render all changed pages (or every page when small), and inspect those images before delivery.
- State which pages were actually extracted or rendered; never claim coverage you did not inspect.
Use shell pipelines and redirection only to connect this fixed managed toolchain or create bounded private intermediates. Use a quoted Python heredoc for short fallback logic, and keep its output explicitly bounded. Do not download packages, invoke pip, Homebrew, or apt, discover the runtime, or expose private paths.
Read the relevant reference before acting:
- [references/reading.md](references/reading.md) for search, page selection, extraction, and visual review.
- [references/creating-and-editing.md](references/creating-and-editing.md) for generation, modification, validation, and delivery.
- [references/forms.md](references/forms.md) for AcroForm inspection, filling, appearance validation, and flattening.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Tiga001
- Source: Tiga001/Captain_Who
- License: Apache-2.0
- Homepage: https://captainwhoagent.com
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.