Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data by providing code to extract text and tables from external PDF files.\n
- Ingestion points: Code snippets in SKILL.md demonstrate reading from files such as
document.pdf,input.pdf, andscanned.pdf.\n - Boundary markers: The provided examples do not include boundary markers or delimiters to help the agent distinguish between instructions and data extracted from the PDF.\n
- Capability inventory: The skill provides the agent with capabilities to write files (
writer.write,to_excel,c.save) and execute shell commands (qpdf,pdftk).\n - Sanitization: There is no evidence of text sanitization or filtering to prevent malicious instructions embedded in a PDF from influencing the agent's behavior.\n- [EXTERNAL_DOWNLOADS]: The documentation recommends the installation of standard Python packages (
pip install pytesseract pdf2image) to handle OCR and image conversion tasks.\n- [COMMAND_EXECUTION]: The skill includes instructions for using established command-line utilities for PDF manipulation, such aspdftotext,qpdf, andpdftk.
Audit Metadata