photo-to-scanned-pdf

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/make_contact_sheet.py executes the system utility pdftoppm using subprocess.run to render PDF pages into images for review. While used for a legitimate purpose, this involves spawning external processes with user-supplied paths.\n- [EXTERNAL_DOWNLOADS]: The skill instructions recommend using uvx noteshrink, which automatically downloads and runs the noteshrink utility from an external repository to perform background whitening and palette quantization.\n- [PROMPT_INJECTION]: The skill relies on the agent reading and verifying the content of user-provided images. This creates a surface for indirect prompt injection if the processed documents contain hidden or visible text instructions designed to manipulate the agent's behavior.\n- [PROMPT_INJECTION]: The presence of the file .security-scan-passed represents a deceptive metadata finding. It contains a simulated security verification log with a future timestamp (2026), which is an untrustworthy claim of safety intended to influence the evaluation of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 05:06 AM
Security Audit — agent-trust-hub — photo-to-scanned-pdf