skills/ethan-rio/skills/ingest-pdf/Gen Agent Trust Hub

ingest-pdf

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to download PDF files from user-supplied URLs provided in the $ARGUMENTS variable. This involves network operations to non-whitelisted domains.
  • [COMMAND_EXECUTION]: The script executes shell utilities including pdftotext, pdfinfo, and wc, and runs an inline Python script using the pypdf library. Although inputs are quoted to mitigate direct command injection, the tools process untrusted external data.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface. 1. Ingestion points: Remote PDF URLs and local file paths. 2. Boundary markers: None are present to encapsulate the extracted text. 3. Capability inventory: The skill has access to Bash, Read, and Write tools, and it executes a local script (new_note.sh). 4. Sanitization: Extracted text is truncated to 40,000 characters, but no content filtering is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — ingest-pdf