document-generation-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The form_filler.ts script includes a hardcoded default password used as a fallback for PDF owner permissions, which could result in predictable security for generated documents if not properly configured in the environment.
  • Evidence: ownerPassword: process.env.PDF_OWNER_PASSWORD || 'owner' in scripts/form_filler.ts and similarly in the encryption examples in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data to generate documents without performing sanitization, creating a potential surface for indirect injection if the resulting PDFs are processed by downstream agents.
  • Ingestion points: The skill reads data from JSON files in scripts/form_filler.ts and scripts/document_assembler.ts.
  • Boundary markers: No explicit boundary markers or "ignore instructions" delimiters are used for the interpolated data fields.
  • Capability inventory: The skill utilizes file system writes (fs.writeFileSync) and is granted Bash tool access for package management and LaTeX processing.
  • Sanitization: There is no evidence of text sanitization or escaping of user-provided strings before they are rendered into the PDF templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — document-generation-pdf