How do I safely read them from the remote box, assuming we really expect the box to get compromised?
If the box is compromised and I RDP, I can get mashed by an RDP exploit. If I download the image or pdf, I can get mashed with an image or PDF exploit.
This is why I never trusted the Qubes image/PDF disarm workflow