visa-doc-translate

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill requires the agent to generate and execute a Python script at runtime to create the final bilingual PDF document using the PIL and reportlab libraries.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface where malicious instructions embedded in images could be processed by the agent during OCR extraction.
  • Ingestion points: Text is extracted from user-uploaded images (bank statements, IDs, passports) using OCR frameworks as defined in SKILL.md.
  • Boundary markers: There are no protective delimiters or instructions to ignore embedded commands within the extracted text.
  • Capability inventory: The skill allows for shell command execution (sips), package installation (pip, brew), and execution of generated Python scripts.
  • Sanitization: The instructions do not specify any validation or sanitization of the OCR-extracted text before it is translated or included in the PDF script.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands for image format conversion (sips) and depends on system-level package managers (brew, pip) to set up the execution environment.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of several external Python libraries and system tools from well-known registries, including easyocr, pytesseract, and reportlab, to perform its document processing functions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — visa-doc-translate