extract-pdf
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill executes commands within an external directory specified by the
PDF_OXIDE_ROOTenvironment variable, which defaults to a path outside the skill's distribution. This creates a risk where code not provided with the skill can be executed at runtime. - Evidence:
run.shcontainsexec uv run --directory "$PDF_OXIDE_ROOT". - Evidence:
sanity.shcontainsuv run --directory "$PDF_OXIDE_ROOT". - [DYNAMIC_EXECUTION]: The skill uses
joblibfor deserialization, which can execute arbitrary code when loading maliciously crafted model files. The model is loaded from a path in the user's home directory. - Evidence:
extract_pdf/cascade/wiring.pyusesjoblib.load()on a path targeting~/.pi/models/classifiers/header_verdict.joblib. - [DYNAMIC_EXECUTION]: The skill dynamically modifies
sys.pathto import code from a directory located several levels above the current file, which is an unsafe practice that can lead to unexpected code execution. - Evidence:
extract_pdf/cascade/wiring.pyaddsPath(__file__).resolve().parents[3] / "common"tosys.path. - [INDIRECT_PROMPT_INJECTION]: The React-based viewer component allows fetching and rendering data from arbitrary URLs via a browser query parameter, creating a surface for cross-site scripting or indirect prompt injection if the agent processes the rendered content.
- Ingestion points:
viewer/src/loader.tsextracts a URL fromwindow.location.search. - Boundary markers: Absent; the viewer fetches and normalizes raw JSON data directly.
- Capability inventory: The viewer displays text blocks, section titles, and taxonomy tags which could contain embedded instructions targeting the AI agent.
- Sanitization: Absent; the data is fetched and passed to the UI state without validation or escaping.
- [COMMAND_EXECUTION]: The execution script sources a
.envfile from a parent directory relative to the skill's location, which could lead to credential injection or environment manipulation if the workspace structure is compromised. - Evidence:
run.shcontainssource "$PROJECT_ROOT/.env".
Recommendations
- AI detected serious security threats
Audit Metadata