photo-to-scanned-pdf
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/make_contact_sheet.pyexecutes the system utilitypdftoppmusingsubprocess.runto render PDF pages into images for review. While used for a legitimate purpose, this involves spawning external processes with user-supplied paths.\n- [EXTERNAL_DOWNLOADS]: The skill instructions recommend usinguvx noteshrink, which automatically downloads and runs thenoteshrinkutility from an external repository to perform background whitening and palette quantization.\n- [PROMPT_INJECTION]: The skill relies on the agent reading and verifying the content of user-provided images. This creates a surface for indirect prompt injection if the processed documents contain hidden or visible text instructions designed to manipulate the agent's behavior.\n- [PROMPT_INJECTION]: The presence of the file.security-scan-passedrepresents a deceptive metadata finding. It contains a simulated security verification log with a future timestamp (2026), which is an untrustworthy claim of safety intended to influence the evaluation of the skill.
Audit Metadata