Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF documents, creating a surface for potential indirect prompt injection attacks if the PDF content contains instructions for the agent.
- Ingestion points: Multiple scripts such as extract_form_field_info.py and extract_form_structure.py ingest PDF content directly.
- Boundary markers: No specific boundary markers or 'ignore' instructions are used when reading extracted text.
- Capability inventory: The skill can write files and execute local command-line tools based on the content processed.
- Sanitization: Extracted text is not sanitized before being printed or processed by the agent.
- [DYNAMIC_EXECUTION]: The script scripts/fill_fillable_fields.py uses runtime monkeypatching to adjust the pypdf library's internal handling of form field attributes. This is a legitimate functional override for compatibility with complex PDF structures but involves modifying library code at runtime.
Audit Metadata