reference
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill documents methods for extracting text and metadata from PDF files using tools like
pypdfium2,pdfjs-dist, andpdfplumber. PDF documents are untrusted external data sources and can contain hidden instructions (indirect prompt injection) intended to override the agent's logic once processed. - Ingestion points:
SKILL.mdincludes code snippets forpage.get_text(),page.getTextContent(),pdftotext,page.extract_text(), andpytesseract.image_to_string(). - Boundary markers: The provided examples do not use delimiters or explicit instructions to treat extracted content strictly as data.
- Capability inventory: The skill outlines several powerful capabilities including file writing (
fs.writeFileSync,writer.write) and command execution (qpdf,poppler-utils) that could be exploited if an injection succeeds. - Sanitization: No sanitization or validation of the extracted text content is demonstrated in the examples.
- [COMMAND_EXECUTION]: The skill provides documentation for utilizing CLI utilities such as
pdftotext,pdftoppm,pdfimages, andqpdf. These tools are invoked via shell commands, which necessitates careful handling of input parameters to prevent command injection vulnerabilities if arguments are derived from untrusted user data.
Audit Metadata