visa-doc-translate

Warn

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands and scripts without user confirmation.
  • It uses sips for image conversion and brew install for system-level dependencies (Tesseract).
  • It uses pip install for various Python libraries.
  • Most critically, it generates a custom Python script using PIL and reportlab at runtime and executes it to create the final PDF document.
  • [EXTERNAL_DOWNLOADS]: The skill downloads and installs several dependencies from public registries.
  • It installs Python packages: pillow, reportlab, easyocr, pytesseract, pyobjc-framework-Vision, and pyobjc-framework-Quartz from PyPI.
  • It installs system packages: tesseract and tesseract-lang via Homebrew.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its document processing workflow.
  • Ingestion points: Text is extracted via OCR from user-provided images (e.g., bank statements, ID cards).
  • Boundary markers: There are no delimiters or instructions to ignore malicious text embedded within the images.
  • Capability inventory: The agent has the ability to execute shell commands (sips, pip, brew) and run dynamically generated Python scripts (SKILL.md).
  • Sanitization: The skill does not describe any sanitization or validation of the text extracted via OCR before it is interpolated into the PDF generation script or the translation prompt. Maliciously crafted text in an image could potentially influence the script generation or the agent's behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — visa-doc-translate