Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted PDF documents through various scripts and tools. Extracted text and metadata from these documents are passed to the agent, creating a vulnerability where malicious instructions embedded in a PDF could influence the agent's behavior.
- Ingestion points: Multiple scripts including
scripts/extract_form_field_info.py,scripts/fill_fillable_fields.py, andscripts/convert_pdf_to_images.pyread data from external PDF files. - Boundary markers: No explicit delimiters or instructions are provided to the agent to disregard potentially malicious content embedded within the extracted PDF data.
- Capability inventory: The skill possesses significant capabilities, including file system read/write, PDF modification via
pypdf, image generation viapdf2image, and shell command execution for PDF utilities. - Sanitization: No sanitization or validation of extracted text content was identified in the provided scripts.
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyperforms monkeypatching at runtime. It replaces theDictionaryObject.get_inheritedmethod in thepypdflibrary with a custom implementation to address a selection list formatting bug. While appearing to be a bug fix, this technique of modifying library behavior at runtime is a form of dynamic execution. - [EXTERNAL_DOWNLOADS]: The skill relies on numerous external libraries and tools, including
reportlab,pypdf,pdfplumber,pdf2image,pypdfium2,pytesseract,pdf-lib, andpdfjs-dist. These are well-known open-source packages and services. - [COMMAND_EXECUTION]: The skill workflow involves executing several command-line utilities for PDF processing, such as
pdftoppm,pdftotext,pdfimages, andqpdf, typically invoked via subprocess calls in the scripts or through manual instructions in the documentation.
Audit Metadata