debug-pdf
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses the
httpxlibrary and a siblingfetcherskill to download PDF files from user-supplied URLs indp_core.py. While it includes ais_valid_urlhelper to restrict schemes to http/https and reject control characters, it still allows the agent to fetch content from any external domain. - [COMMAND_EXECUTION]: The skill frequently uses
subprocess.runto interact with other tools and skills within the environment. This includes calling thefetcher,memory,extractor, andagent-inboxskills, as well as theuvpackage manager to run reproduction scripts from thefixture-trickyskill. These calls use argument lists which mitigate shell injection risks. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its data processing pipeline:
- Ingestion points: Untrusted content is ingested via
download_pdfand text is extracted usingpymupdfinanalyze_pdf(dp_core.py) and various detectors. - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands when the extracted PDF text is passed to the
memoryoragent-inboxskills. - Capability inventory: The skill possesses capabilities to perform network downloads and execute other system-level skills via
subprocess.run. - Sanitization: Extracted PDF text is used verbatim in logging, notifications, and memory storage (
memory_learnindp_core.py) without filtering or escaping potentially malicious instructions embedded in the document.
Audit Metadata