document-generation-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
form_filler.tsscript includes a hardcoded default password used as a fallback for PDF owner permissions, which could result in predictable security for generated documents if not properly configured in the environment. - Evidence:
ownerPassword: process.env.PDF_OWNER_PASSWORD || 'owner'inscripts/form_filler.tsand similarly in the encryption examples inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted external data to generate documents without performing sanitization, creating a potential surface for indirect injection if the resulting PDFs are processed by downstream agents.
- Ingestion points: The skill reads data from JSON files in
scripts/form_filler.tsandscripts/document_assembler.ts. - Boundary markers: No explicit boundary markers or "ignore instructions" delimiters are used for the interpolated data fields.
- Capability inventory: The skill utilizes file system writes (
fs.writeFileSync) and is grantedBashtool access for package management and LaTeX processing. - Sanitization: There is no evidence of text sanitization or escaping of user-provided strings before they are rendered into the PDF templates.
Audit Metadata