skills/ethan-rio/skills/Chat with PDF/Gen Agent Trust Hub

Chat with PDF

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional and utilizes standard MCP tools (extract_text_from_pdf, get_pdf_metadata) for its intended purpose. No instances of obfuscation, hardcoded credentials, or unauthorized network operations were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing untrusted external PDF content, which constitutes an indirect prompt injection surface. However, the risk is negligible as the skill lacks 'sink' capabilities such as file system writes or non-whitelisted network exfiltration tools, meaning any potential injection would be confined to the immediate conversation context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:55 AM
Security Audit — agent-trust-hub — Chat with PDF