pdf-extraction

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides standard documentation and Python examples for extracting text and tables from PDF files. The code snippets use the established pdfplumber library for its intended purpose, with no evidence of malicious command execution, data exfiltration, or obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process external PDF files, it possesses a surface for indirect prompt injection. This is inherent to the skill's primary function of data ingestion.
  • Ingestion points: Functions like extract_invoice_data and parse_resume in SKILL.md open and read user-provided PDF files.
  • Boundary markers: The examples do not include explicit instructions to ignore potentially malicious content within the PDFs.
  • Capability inventory: Includes file read access for PDFs and file write capabilities for exporting images and Excel reports.
  • Sanitization: The provided extraction logic does not perform sanitization or validation of the text content extracted from the documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:53 PM
Security Audit — agent-trust-hub — pdf-extraction