skills/claudiodearaujo/izacenter/pdf/Gen Agent Trust Hub

pdf

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted PDF documents, which creates a potential surface for indirect prompt injection. * Ingestion points: The skill reads PDF files in extract_form_field_info.py, fill_fillable_fields.py, and convert_pdf_to_images.py. It also reads fields.json which is generated from PDF analysis. * Boundary markers: No explicit boundary markers or instructions to ignore embedded content are used when extracting text for the agent to process. * Capability inventory: The skill has capabilities to write files (writer.write, image.save) and execute various Python and CLI tools. * Sanitization: Text content extracted from PDFs is not sanitized or filtered before being presented to the agent.
  • [DYNAMIC_EXECUTION]: The script scripts/fill_fillable_fields.py implements a runtime monkeypatch using monkeypatch_pydpf_method(). This function replaces the get_inherited method of the pypdf.generic.DictionaryObject class to correct a TypeError bug when processing selection list fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:32 PM
Security Audit — agent-trust-hub — pdf