pdf

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external PDF documents through multiple tools including pdftotext, pdfplumber, and extract_form_field_info.py. This creates a vulnerability surface for indirect prompt injection, where malicious instructions embedded in a PDF could influence the agent's behavior during text extraction or form analysis.
  • Ingestion points: Text extraction in SKILL.md (via pdftotext and pdfplumber) and form field extraction in FORMS.md (via scripts/extract_form_field_info.py).
  • Boundary markers: None identified; instructions do not explicitly tell the agent to ignore instructions found within document content.
  • Capability inventory: The skill has significant capabilities including file system access (read/write), image processing, and execution of shell-based PDF utilities (qpdf, pdftk, poppler-utils).
  • Sanitization: Extraction scripts do not appear to sanitize or escape extracted text to prevent it from being interpreted as instructions by the LLM.
  • [DYNAMIC_EXECUTION]: The script scripts/fill_fillable_fields.py performs runtime modification of a third-party library's behavior.
  • Evidence: The monkeypatch_pydpf_method function redefines the get_inherited method of the pypdf.generic.DictionaryObject class to address a specific bug in selection list handling. While this is a targeted compatibility fix, modifying library behavior at runtime is a form of dynamic execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 06:09 AM
Security Audit — agent-trust-hub — pdf