Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract text and process data from external PDF documents using libraries like pypdf and pdfplumber, as well as OCR via pytesseract. This creates a surface for indirect prompt injection, where an attacker could embed malicious instructions within a PDF file that the agent might inadvertently follow when processing the document's content.
- [DYNAMIC_EXECUTION]: The file
scripts/fill_fillable_fields.pycontains a functionmonkeypatch_pydpf_methodthat modifies thepypdf.generic.DictionaryObject.get_inheritedmethod at runtime. This is intended to work around a specific bug in pypdf version 5.7.0 related to selection list fields. Although documented as a bug fix, runtime modification of library code is a dynamic execution pattern. - [COMMAND_EXECUTION]: The
SKILL.mdandreference.mdfiles provide numerous command-line snippets for utilities such asqpdf,pdftotext,pdfimages, andpdftk. The agent is instructed to use these tools for merging, splitting, and extracting data from PDF files, which involves shell command execution.
Audit Metadata