Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
os.shell.runtool to execute system commands for PDF processing (qpdf,poppler,ocrmypdf). It also provides functionality to install these tools viabreworapt-getif they are missing from the host environment. - [EXTERNAL_DOWNLOADS]: The skill initiates downloads of system-level utilities from official repositories using platform-standard package managers (
Homebrewfor macOS,aptfor Linux). These are recognized tools for the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF files which serves as an ingestion point for external data. This content is processed using shell tools and
os.fs.read_document. While the skill includes a rule to treat PDF contents as untrusted, there are no explicit boundary markers or sanitization steps documented for interpolating data into shell arguments, creating a potential surface for instructions embedded within PDFs to influence agent behavior. - Ingestion points: Reads PDF text and metadata via
os.fs.read_documentand CLI tools likepdfinfoandpdftotext(SKILL.md). - Boundary markers: None identified in the prompt templates.
- Capability inventory: Uses
os.shell.runfor command execution andos.fs.read_documentfor file access (SKILL.md). - Sanitization: No specific sanitization or filtering logic is defined for the data extracted from PDF files before further processing.
Audit Metadata