Chat with PDF
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is entirely instructional and utilizes standard MCP tools (extract_text_from_pdf, get_pdf_metadata) for its intended purpose. No instances of obfuscation, hardcoded credentials, or unauthorized network operations were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing untrusted external PDF content, which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks 'sink' capabilities such as file system writes or non-whitelisted network exfiltration tools, meaning any potential injection would be confined to the immediate conversation context.
Audit Metadata