skills/atomicbot-ai/atomic-agent/pdf/Gen Agent Trust Hub

pdf

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the os.shell.run tool to execute system commands for PDF processing (qpdf, poppler, ocrmypdf). It also provides functionality to install these tools via brew or apt-get if they are missing from the host environment.
  • [EXTERNAL_DOWNLOADS]: The skill initiates downloads of system-level utilities from official repositories using platform-standard package managers (Homebrew for macOS, apt for Linux). These are recognized tools for the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF files which serves as an ingestion point for external data. This content is processed using shell tools and os.fs.read_document. While the skill includes a rule to treat PDF contents as untrusted, there are no explicit boundary markers or sanitization steps documented for interpolating data into shell arguments, creating a potential surface for instructions embedded within PDFs to influence agent behavior.
  • Ingestion points: Reads PDF text and metadata via os.fs.read_document and CLI tools like pdfinfo and pdftotext (SKILL.md).
  • Boundary markers: None identified in the prompt templates.
  • Capability inventory: Uses os.shell.run for command execution and os.fs.read_document for file access (SKILL.md).
  • Sanitization: No specific sanitization or filtering logic is defined for the data extracted from PDF files before further processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:32 PM
Security Audit — agent-trust-hub — pdf