Warn
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyimplements a monkeypatch on thepypdflibrary at runtime. It replaces theDictionaryObject.get_inheritedmethod with a custom implementation designed to work around a data structure error in the library's handling of selection list options in version 5.7.0. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function is processing external PDF files, which represents an ingestion point for untrusted data that could contain malicious instructions.
- Ingestion points: The skill utilizes
pypdf,pdfplumber, andpdf2imageto parse and extract data from PDF documents (seen inSKILL.mdand various utility scripts). - Boundary markers: No explicit delimiters or instructions are provided to the agent to treat document content as untrusted or to ignore embedded instructions.
- Capability inventory: The skill possesses the capability to write files and instructs the agent to execute shell commands and local Python scripts.
- Sanitization: Extracted data is not explicitly sanitized before being used in the agent's workflow, potentially allowing malicious content within a PDF to influence agent behavior.
- [COMMAND_EXECUTION]: The operational guides in
forms.mdandSKILL.mdprovide explicit instructions for the agent to execute local Python scripts and command-line utilities, includingqpdf,pdftotext, andpdfimages, to perform document analysis and transformation tasks.
Audit Metadata