pdf-explore

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill provides guidelines for the agent to follow when processing PDF documents. It does not include any scripts, executable code, or shell commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process scientific PDFs from external sources, which constitutes an untrusted data ingestion surface.\n
  • Ingestion points: Scientific PDF documents provided by the user at runtime in SKILL.md workflow.\n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are defined in the workflow steps.\n
  • Capability inventory: The agent is instructed to parse content, extract specific regions (tables, figures, accession IDs), and save results as artifacts.\n
  • Sanitization: The instructions do not include steps to sanitize, escape, or filter the extracted text for potentially malicious instructions hidden within the PDF content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 02:09 PM
Security Audit — agent-trust-hub — pdf-explore