Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external PDF documents through multiple tools including
pdftotext,pdfplumber, andextract_form_field_info.py. This creates a vulnerability surface for indirect prompt injection, where malicious instructions embedded in a PDF could influence the agent's behavior during text extraction or form analysis. - Ingestion points: Text extraction in
SKILL.md(viapdftotextandpdfplumber) and form field extraction inFORMS.md(viascripts/extract_form_field_info.py). - Boundary markers: None identified; instructions do not explicitly tell the agent to ignore instructions found within document content.
- Capability inventory: The skill has significant capabilities including file system access (read/write), image processing, and execution of shell-based PDF utilities (
qpdf,pdftk,poppler-utils). - Sanitization: Extraction scripts do not appear to sanitize or escape extracted text to prevent it from being interpreted as instructions by the LLM.
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyperforms runtime modification of a third-party library's behavior. - Evidence: The
monkeypatch_pydpf_methodfunction redefines theget_inheritedmethod of thepypdf.generic.DictionaryObjectclass to address a specific bug in selection list handling. While this is a targeted compatibility fix, modifying library behavior at runtime is a form of dynamic execution.
Audit Metadata