tesseract
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the conversion of image data into text, which represents a surface for indirect prompt injection where malicious text in an image could override agent instructions.
- Ingestion points: External image files processed via the tesseract CLI (SKILL.md).
- Boundary markers: The instructions do not include prompt delimiters or warnings to ignore instructions found within OCR output.
- Capability inventory: Shell access to execute the tesseract command.
- Sanitization: No methods for sanitizing or filtering the extracted text are provided.
Audit Metadata