processing-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF files, which constitutes a potential surface for indirect prompt injection if a processed document contains malicious instructions.
- Ingestion points: Untrusted data enters the agent context via PDF files read by
pdfplumber,pypdf, andpypdfium2across all scripts in thescripts/directory. - Boundary markers: None identified. Extracted text is presented to the agent or written to files without explicit delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill can write files (CSV, PNG, and PDF) and dispatch tasks to other agents (e.g.,
pdf-extractor). - Sanitization: None identified. Text extraction is performed on the raw content of the provided PDF files.
- [SAFE]: The skill follows security best practices by recommending the use of a virtual environment and standard system tools for metadata and text extraction. All scripts perform their stated functions without hidden behaviors or network exfiltration.
Audit Metadata