pdf

Fail

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the agent to use sudo apt-get install -y poppler-utils. This involves the use of sudo to gain administrative privileges, which is a high-risk action that could lead to unauthorized system modification or compromise.
  • [COMMAND_EXECUTION]: The rendering workflow includes the command pdftoppm -png $INPUT_PDF $OUTPUT_PREFIX. The use of shell variables without explicit sanitization instructions presents a risk of command injection if the filenames are derived from untrusted user input.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing untrusted data found within PDF documents, which could lead to the agent following malicious instructions embedded in those files.
  • Ingestion points: Reading PDF content using pdfplumber or pypdf as described in the workflow section.
  • Boundary markers: None identified; the skill lacks instructions for using delimiters or warnings to ignore embedded content.
  • Capability inventory: Subprocess execution for rendering and file system writes to specified temporary and output directories.
  • Sanitization: No procedures for validating PDF sources or sanitizing extracted text are provided.
  • [EXTERNAL_DOWNLOADS]: The skill references dependencies and system tools to be installed from well-known registries including PyPI, Homebrew, and the Ubuntu/Debian package repositories.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 21, 2026, 02:00 PM
Security Audit — agent-trust-hub — pdf