processing-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF files, which constitutes a potential surface for indirect prompt injection if a processed document contains malicious instructions.
  • Ingestion points: Untrusted data enters the agent context via PDF files read by pdfplumber, pypdf, and pypdfium2 across all scripts in the scripts/ directory.
  • Boundary markers: None identified. Extracted text is presented to the agent or written to files without explicit delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill can write files (CSV, PNG, and PDF) and dispatch tasks to other agents (e.g., pdf-extractor).
  • Sanitization: None identified. Text extraction is performed on the raw content of the provided PDF files.
  • [SAFE]: The skill follows security best practices by recommending the use of a virtual environment and standard system tools for metadata and text extraction. All scripts perform their stated functions without hidden behaviors or network exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — processing-pdf