Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to utilize standard command-line tools for PDF operations, including
qpdf,pdftotext,pdftk, andpdftoppm. These tools are used for merging, splitting, and converting documents as part of the primary PDF processing workflow. - [REMOTE_CODE_EXECUTION]: The script
scripts/fill_fillable_fields.pyimplements a monkeypatch for thepypdflibrary to fix a known issue with selection list formatting. This runtime modification is limited to a specific library method (DictionaryObject.get_inherited) to ensure correct form field processing. - [PROMPT_INJECTION]: The skill processes untrusted PDF files to extract content and metadata, which creates a potential surface for indirect prompt injection. A malicious PDF could contain text designed to override agent instructions during analysis.
- Ingestion points: Data is ingested from external PDFs via
scripts/extract_form_field_info.pyandscripts/convert_pdf_to_images.py. - Boundary markers: The skill does not implement explicit boundary markers or warnings to ignore instructions found within extracted PDF text.
- Capability inventory: The skill has permissions to write files to the local system and execute external command-line utilities.
- Sanitization: No specialized sanitization or filtering is applied to extracted PDF text before it is presented to the agent for decision-making.
Audit Metadata