reference

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill documents methods for extracting text and metadata from PDF files using tools like pypdfium2, pdfjs-dist, and pdfplumber. PDF documents are untrusted external data sources and can contain hidden instructions (indirect prompt injection) intended to override the agent's logic once processed.
  • Ingestion points: SKILL.md includes code snippets for page.get_text(), page.getTextContent(), pdftotext, page.extract_text(), and pytesseract.image_to_string().
  • Boundary markers: The provided examples do not use delimiters or explicit instructions to treat extracted content strictly as data.
  • Capability inventory: The skill outlines several powerful capabilities including file writing (fs.writeFileSync, writer.write) and command execution (qpdf, poppler-utils) that could be exploited if an injection succeeds.
  • Sanitization: No sanitization or validation of the extracted text content is demonstrated in the examples.
  • [COMMAND_EXECUTION]: The skill provides documentation for utilizing CLI utilities such as pdftotext, pdftoppm, pdfimages, and qpdf. These tools are invoked via shell commands, which necessitates careful handling of input parameters to prevent command injection vulnerabilities if arguments are derived from untrusted user data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 12:54 PM
Security Audit — agent-trust-hub — reference