skills/andrewhaward2310/.agents/pdf/Gen Agent Trust Hub

pdf

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing untrusted PDF documents to extract text and structured data.
  • Ingestion points: The skill reads external PDF files in SKILL.md, scripts/extract_form_field_info.py, and scripts/fill_fillable_fields.py to extract text, tables, and form metadata.
  • Boundary markers: Absent. There are no instructions or delimiters defined to help the agent distinguish between its operational instructions and the potentially adversarial content within the processed PDFs.
  • Capability inventory: The skill has access to the file system (read/write) and shell command execution via the agent's environment to run PDF CLI tools.
  • Sanitization: Absent. Extracted data is not sanitized before being returned to the agent's context.
  • [COMMAND_EXECUTION]: The skill relies on external command-line utilities and performs dynamic code modification at runtime.
  • Evidence: SKILL.md and reference.md provide numerous examples for executing qpdf, pdftotext, pdftk, and pdfimages shell commands.
  • Evidence: scripts/fill_fillable_fields.py contains a monkeypatch_pydpf_method function that dynamically replaces the get_inherited method in the pypdf library at runtime to fix an upstream formatting bug.
  • [SAFE]: External library dependencies and downloads target established, well-known software providers.
  • Evidence: The skill utilizes standard PDF libraries including pypdf, pdfplumber, reportlab, and pypdfium2.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — pdf