document-pro
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes content from untrusted external documents. \n- Ingestion points: Data is ingested from PDF, DOCX, PPTX, and XLSX files using the libraries listed in SKILL.md. \n- Boundary markers: Absent. The skill does not instruct the agent to use delimiters or ignore embedded instructions when reading document text. \n- Capability inventory: The skill contains instructions and code examples for reading and extracting information from documents using pdfplumber, PyPDF2, python-docx, python-pptx, and openpyxl. No evidence of data exfiltration or unauthorized command execution was found. \n- Sanitization: Absent. There are no mechanisms for sanitizing or validating extracted content before it is processed by the agent context.
Audit Metadata