Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted PDF documents, which creates a potential surface for indirect prompt injection. * Ingestion points: The skill reads PDF files in
extract_form_field_info.py,fill_fillable_fields.py, andconvert_pdf_to_images.py. It also readsfields.jsonwhich is generated from PDF analysis. * Boundary markers: No explicit boundary markers or instructions to ignore embedded content are used when extracting text for the agent to process. * Capability inventory: The skill has capabilities to write files (writer.write,image.save) and execute various Python and CLI tools. * Sanitization: Text content extracted from PDFs is not sanitized or filtered before being presented to the agent. - [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyimplements a runtime monkeypatch usingmonkeypatch_pydpf_method(). This function replaces theget_inheritedmethod of thepypdf.generic.DictionaryObjectclass to correct a TypeError bug when processing selection list fields.
Audit Metadata