extract-pdf

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill executes commands within an external directory specified by the PDF_OXIDE_ROOT environment variable, which defaults to a path outside the skill's distribution. This creates a risk where code not provided with the skill can be executed at runtime.
  • Evidence: run.sh contains exec uv run --directory "$PDF_OXIDE_ROOT".
  • Evidence: sanity.sh contains uv run --directory "$PDF_OXIDE_ROOT".
  • [DYNAMIC_EXECUTION]: The skill uses joblib for deserialization, which can execute arbitrary code when loading maliciously crafted model files. The model is loaded from a path in the user's home directory.
  • Evidence: extract_pdf/cascade/wiring.py uses joblib.load() on a path targeting ~/.pi/models/classifiers/header_verdict.joblib.
  • [DYNAMIC_EXECUTION]: The skill dynamically modifies sys.path to import code from a directory located several levels above the current file, which is an unsafe practice that can lead to unexpected code execution.
  • Evidence: extract_pdf/cascade/wiring.py adds Path(__file__).resolve().parents[3] / "common" to sys.path.
  • [INDIRECT_PROMPT_INJECTION]: The React-based viewer component allows fetching and rendering data from arbitrary URLs via a browser query parameter, creating a surface for cross-site scripting or indirect prompt injection if the agent processes the rendered content.
  • Ingestion points: viewer/src/loader.ts extracts a URL from window.location.search.
  • Boundary markers: Absent; the viewer fetches and normalizes raw JSON data directly.
  • Capability inventory: The viewer displays text blocks, section titles, and taxonomy tags which could contain embedded instructions targeting the AI agent.
  • Sanitization: Absent; the data is fetched and passed to the UI state without validation or escaping.
  • [COMMAND_EXECUTION]: The execution script sources a .env file from a parent directory relative to the skill's location, which could lead to credential injection or environment manipulation if the workspace structure is compromised.
  • Evidence: run.sh contains source "$PROJECT_ROOT/.env".
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — extract-pdf