debug-pdf

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses the httpx library and a sibling fetcher skill to download PDF files from user-supplied URLs in dp_core.py. While it includes a is_valid_url helper to restrict schemes to http/https and reject control characters, it still allows the agent to fetch content from any external domain.
  • [COMMAND_EXECUTION]: The skill frequently uses subprocess.run to interact with other tools and skills within the environment. This includes calling the fetcher, memory, extractor, and agent-inbox skills, as well as the uv package manager to run reproduction scripts from the fixture-tricky skill. These calls use argument lists which mitigate shell injection risks.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection (Category 8) due to its data processing pipeline:
  • Ingestion points: Untrusted content is ingested via download_pdf and text is extracted using pymupdf in analyze_pdf (dp_core.py) and various detectors.
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands when the extracted PDF text is passed to the memory or agent-inbox skills.
  • Capability inventory: The skill possesses capabilities to perform network downloads and execute other system-level skills via subprocess.run.
  • Sanitization: Extracted PDF text is used verbatim in logging, notifications, and memory storage (memory_learn in dp_core.py) without filtering or escaping potentially malicious instructions embedded in the document.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — debug-pdf