Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted PDF documents which presents a potential vulnerability surface for instructions embedded in data.\n
- Ingestion points: Untrusted data is ingested via PDF files in
scripts/extract_form_field_info.py,scripts/fill_fillable_fields.py, andscripts/fill_pdf_form_with_annotations.py.\n - Boundary markers: No explicit prompt boundary markers are used; the skill relies on instructional workflow guidance in
forms.md.\n - Capability inventory: The skill possesses capabilities for file system operations, execution of PDF utility shell commands, and runtime library modification.\n
- Sanitization: Employs geometric validation for bounding boxes in
scripts/check_bounding_boxes.pyand field value validation inscripts/fill_fillable_fields.py.\n- [DYNAMIC_EXECUTION]: The scriptscripts/fill_fillable_fields.pyperforms runtime monkeypatching on thepypdflibrary to fix a known issue with handling selection list fields.
Audit Metadata