visa-doc-translate
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to handle image conversion and environment setup. It utilizes the macOS
sipstool to convert HEIC files to PNG and executespipandbrewcommands to install necessary OCR and PDF libraries. - [REMOTE_CODE_EXECUTION]: The skill dynamically generates and executes a Python script at runtime. This script is used to center the original document image and format the English translation into a two-page PDF using the
reportlablibrary. - [EXTERNAL_DOWNLOADS]: To perform its tasks, the skill installs several standard third-party libraries including
pillow,reportlab,easyocr, andpytesseract. It also downloads the Tesseract OCR engine using Homebrew. - [PROMPT_INJECTION]: The skill has a potential indirect prompt injection surface because it processes text extracted from user-provided images via OCR.
- Ingestion points: Text content is ingested from images provided by the user in
SKILL.md. - Boundary markers: There are no specific instructions or delimiters provided to the agent to distinguish between the document content and potential instructions embedded in that content.
- Capability inventory: The agent can execute shell commands (
sips,pip,brew) and generate/execute Python scripts. - Sanitization: No sanitization or filtering is performed on the extracted text before it is translated or used in the PDF generation process.
Audit Metadata