Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and extract text from user-provided PDF files, which can lead to indirect prompt injection if those files contain malicious instructions.
- Ingestion points: Text, labels, and structure are extracted from external PDFs in
scripts/extract_form_structure.py,scripts/extract_form_field_info.py, andscripts/check_fillable_fields.py. - Boundary markers: The skill instructions do not specify the use of delimiters or boundary markers (e.g., XML tags or clear separators) when presenting extracted PDF content to the agent.
- Capability inventory: The skill has capabilities to write files to the local system (
PdfWriter), create images (pdf2image), and execute local utility scripts via the shell. - Sanitization: The extraction scripts do not include sanitization or filtering logic to strip potential instructions from the extracted PDF text before processing.
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyutilizes runtime monkeypatching to modify the behavior of thepypdflibrary. - Evidence: The
monkeypatch_pydpf_methodfunction redefinesDictionaryObject.get_inheritedat runtime to alter howFieldDictionaryAttributes.Optvalues are handled. While this is a common developer technique for task-specific workarounds in Python, it represents dynamic modification of executable code logic.
Audit Metadata