pdfkit

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill exclusively provides educational documentation and Swift code snippets for the official Apple PDFKit framework. All code patterns follow standard iOS and macOS development practices for loading, displaying, and annotating PDF documents.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents methods for extracting text and form data from PDF files (e.g., document.string, annotation.widgetStringValue). This identifies an attack surface where malicious instructions could be embedded in PDF content. 1. Ingestion points: PDFDocument(url:) and PDFDocument(data:) initialization in SKILL.md. 2. Boundary markers: Absent from the provided snippets. 3. Capability inventory: System calls for writing files (document.write), printing (UIPrintInteractionController), and opening URLs (UIApplication.shared.open). 4. Sanitization: Not present in the educational code patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 11:25 PM
Security Audit — agent-trust-hub — pdfkit