pdf-extraction
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides standard documentation and Python examples for extracting text and tables from PDF files. The code snippets use the established
pdfplumberlibrary for its intended purpose, with no evidence of malicious command execution, data exfiltration, or obfuscation. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to process external PDF files, it possesses a surface for indirect prompt injection. This is inherent to the skill's primary function of data ingestion.
- Ingestion points: Functions like
extract_invoice_dataandparse_resumeinSKILL.mdopen and read user-provided PDF files. - Boundary markers: The examples do not include explicit instructions to ignore potentially malicious content within the PDFs.
- Capability inventory: Includes file read access for PDFs and file write capabilities for exporting images and Excel reports.
- Sanitization: The provided extraction logic does not perform sanitization or validation of the text content extracted from the documents.
Audit Metadata