pdfkit
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill exclusively provides educational documentation and Swift code snippets for the official Apple PDFKit framework. All code patterns follow standard iOS and macOS development practices for loading, displaying, and annotating PDF documents.
- [INDIRECT_PROMPT_INJECTION]: The skill documents methods for extracting text and form data from PDF files (e.g.,
document.string,annotation.widgetStringValue). This identifies an attack surface where malicious instructions could be embedded in PDF content. 1. Ingestion points:PDFDocument(url:)andPDFDocument(data:)initialization inSKILL.md. 2. Boundary markers: Absent from the provided snippets. 3. Capability inventory: System calls for writing files (document.write), printing (UIPrintInteractionController), and opening URLs (UIApplication.shared.open). 4. Sanitization: Not present in the educational code patterns.
Audit Metadata