skills/autumnsgrove/claudeskills/pdf/Gen Agent Trust Hub

pdf

Fail

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: HIGHDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The examples/invoice-generator.md file contains a function generate_invoices_from_csv that uses eval(row['items']) to parse data from a CSV file. This pattern is highly insecure and allows for arbitrary code execution if the CSV file content is controlled by an untrusted source.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external PDF and CSV files (ingestion points in SKILL.md, scripts/pdf_helper.py, and examples/invoice-generator.md). The skill lacks boundary markers or sanitization for general text extraction, creating a vulnerability where hidden instructions in documents could be interpreted by the agent as commands. This surface is particularly concerning as the skill also possesses file-writing capabilities across multiple components (e.g., fitz.Document.save, PdfWriter.write).
  • [EXTERNAL_DOWNLOADS]: Documentation in README.md and references/library-installation.md points to external third-party GitHub repositories (github.com/oschwartz10612/poppler-windows and github.com/UB-Mannheim/tesseract) for binary dependencies. While these are standard resources for these specific tools, they represent unmanaged external dependencies.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 22, 2026, 05:21 PM
Security Audit — agent-trust-hub — pdf