Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyperforms monkeypatching on thepypdflibrary at runtime. Specifically, it overrides theget_inheritedmethod ofpypdf.generic.DictionaryObjectto address a bug in the library's handling of selection list fields. This dynamic modification of an imported library is a notable technique, though here it is used for a documented bug fix. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external PDF documents, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: Data is read from PDFs using libraries such as
pypdfandpdfplumber, and command-line tools likepdftotext, as seen inSKILL.mdandscripts/extract_form_field_info.py. - Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands within the extracted PDF text to protect the agent's context.
- Capability inventory: The skill possesses file system write access (
PdfWriter.write()) and the ability to execute command-line utilities, which could be leveraged if an agent obeys instructions hidden in a document. - Sanitization: Extracted content is provided to the agent without evidence of explicit sanitization or filtering.
- [COMMAND_EXECUTION]: The skill documentation and scripts facilitate the execution of several command-line utilities for PDF manipulation, including
qpdf,pdftotext,pdftk, andpdftoppm. These are standard tools used for merges, splits, text extraction, and document rendering. - [EXTERNAL_DOWNLOADS]: The documentation references and recommends the installation of several well-known third-party libraries to provide its functionality, including
pytesseract,pdf2image,pypdfium2,pdf-lib, andpdfjs-dist.
Audit Metadata