pdf-toolkit
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to audit PDF metadata, which involves ingesting untrusted content from external files. This creates a surface where an attacker could embed malicious instructions in PDF metadata fields (e.g., Author, Title) to influence the agent's behavior during the review process.
- Ingestion points: The
scripts/pdf_auditor.pyscript reads the raw byte content of user-supplied PDF documents to extract metadata and structure information. - Boundary markers: Audit output is structured (JSON or labeled text) but does not include explicit delimiters or "ignore instructions" warnings for the extracted metadata values.
- Capability inventory: The skill uses a read-only Python script with no network, file-write, or shell execution capabilities. It operates strictly within the Python standard library.
- Sanitization: The script includes custom PDF string decoding and basic regex-based tag stripping for XMP metadata, though it does not filter for potential prompt injection patterns within the document fields.
Audit Metadata