Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing untrusted PDF documents to extract text and structured data.
- Ingestion points: The skill reads external PDF files in
SKILL.md,scripts/extract_form_field_info.py, andscripts/fill_fillable_fields.pyto extract text, tables, and form metadata. - Boundary markers: Absent. There are no instructions or delimiters defined to help the agent distinguish between its operational instructions and the potentially adversarial content within the processed PDFs.
- Capability inventory: The skill has access to the file system (read/write) and shell command execution via the agent's environment to run PDF CLI tools.
- Sanitization: Absent. Extracted data is not sanitized before being returned to the agent's context.
- [COMMAND_EXECUTION]: The skill relies on external command-line utilities and performs dynamic code modification at runtime.
- Evidence:
SKILL.mdandreference.mdprovide numerous examples for executingqpdf,pdftotext,pdftk, andpdfimagesshell commands. - Evidence:
scripts/fill_fillable_fields.pycontains amonkeypatch_pydpf_methodfunction that dynamically replaces theget_inheritedmethod in thepypdflibrary at runtime to fix an upstream formatting bug. - [SAFE]: External library dependencies and downloads target established, well-known software providers.
- Evidence: The skill utilizes standard PDF libraries including
pypdf,pdfplumber,reportlab, andpypdfium2.
Audit Metadata