visa-doc-translate

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the native macOS sips command-line utility to convert images from HEIC format to PNG.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install several well-known third-party dependencies, including Python libraries (pillow, reportlab, easyocr, pytesseract) and the tesseract system package via brew.
  • [COMMAND_EXECUTION]: To create the final output, the skill requires the agent to dynamically generate a Python script using the reportlab library and execute it on the local system.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its automated processing of image content.
  • Ingestion points: External image files provided by the user (processed via OCR in SKILL.md).
  • Boundary markers: Absent; there are no delimiters used to separate extracted OCR text from the agent's internal instructions.
  • Capability inventory: The skill has the capability to execute shell commands (sips) and perform dynamic code execution (generated Python scripts in SKILL.md).
  • Sanitization: Absent; the skill does not validate or sanitize the text extracted from documents before including it in the translation and script generation pipeline.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — visa-doc-translate