pdf

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard command-line tools for PDF operations, including qpdf, pdftotext, pdftk, and pdftoppm. These tools are used for merging, splitting, and converting documents as part of the primary PDF processing workflow.
  • [REMOTE_CODE_EXECUTION]: The script scripts/fill_fillable_fields.py implements a monkeypatch for the pypdf library to fix a known issue with selection list formatting. This runtime modification is limited to a specific library method (DictionaryObject.get_inherited) to ensure correct form field processing.
  • [PROMPT_INJECTION]: The skill processes untrusted PDF files to extract content and metadata, which creates a potential surface for indirect prompt injection. A malicious PDF could contain text designed to override agent instructions during analysis.
  • Ingestion points: Data is ingested from external PDFs via scripts/extract_form_field_info.py and scripts/convert_pdf_to_images.py.
  • Boundary markers: The skill does not implement explicit boundary markers or warnings to ignore instructions found within extracted PDF text.
  • Capability inventory: The skill has permissions to write files to the local system and execute external command-line utilities.
  • Sanitization: No specialized sanitization or filtering is applied to extracted PDF text before it is presented to the agent for decision-making.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 05:46 AM
Security Audit — agent-trust-hub — pdf