pdf

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract text and process data from external PDF documents using libraries like pypdf and pdfplumber, as well as OCR via pytesseract. This creates a surface for indirect prompt injection, where an attacker could embed malicious instructions within a PDF file that the agent might inadvertently follow when processing the document's content.
  • [DYNAMIC_EXECUTION]: The file scripts/fill_fillable_fields.py contains a function monkeypatch_pydpf_method that modifies the pypdf.generic.DictionaryObject.get_inherited method at runtime. This is intended to work around a specific bug in pypdf version 5.7.0 related to selection list fields. Although documented as a bug fix, runtime modification of library code is a dynamic execution pattern.
  • [COMMAND_EXECUTION]: The SKILL.md and reference.md files provide numerous command-line snippets for utilities such as qpdf, pdftotext, pdfimages, and pdftk. The agent is instructed to use these tools for merging, splitting, and extracting data from PDF files, which involves shell command execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — pdf