pdf

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and extract text from user-provided PDF files, which can lead to indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: Text, labels, and structure are extracted from external PDFs in scripts/extract_form_structure.py, scripts/extract_form_field_info.py, and scripts/check_fillable_fields.py.
  • Boundary markers: The skill instructions do not specify the use of delimiters or boundary markers (e.g., XML tags or clear separators) when presenting extracted PDF content to the agent.
  • Capability inventory: The skill has capabilities to write files to the local system (PdfWriter), create images (pdf2image), and execute local utility scripts via the shell.
  • Sanitization: The extraction scripts do not include sanitization or filtering logic to strip potential instructions from the extracted PDF text before processing.
  • [DYNAMIC_EXECUTION]: The script scripts/fill_fillable_fields.py utilizes runtime monkeypatching to modify the behavior of the pypdf library.
  • Evidence: The monkeypatch_pydpf_method function redefines DictionaryObject.get_inherited at runtime to alter how FieldDictionaryAttributes.Opt values are handled. While this is a common developer technique for task-specific workarounds in Python, it represents dynamic modification of executable code logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 02:20 PM