Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection through document processing.
- Ingestion points: In
forms.md, the agent is instructed to convert user-supplied PDFs into PNG images and then visually analyze those images to identify form fields and their purposes. - Boundary markers: No explicit boundary markers or instructions to disregard embedded text/commands within the processed images are provided.
- Sanitization: There is no evidence of sanitization or filtering of the content extracted from the PDFs before it is used to influence the agent's next steps.
- Capability inventory: The skill has access to local script execution, file system operations, and image processing, making it vulnerable to malicious instructions embedded within a PDF designed to hijack the agent's workflow during the 'Visual Analysis' phase.
- [COMMAND_EXECUTION]: The skill relies on the execution of several local utility scripts to perform its functions.
- Instructions in
forms.mddirect the agent to run multiple Python scripts (e.g.,extract_form_field_info.py,convert_pdf_to_images.py,fill_fillable_fields.py) via the command line. - These scripts take user-provided filenames and JSON data as arguments, which could be exploited if the scripts do not properly sanitize input or if they are manipulated to execute arbitrary code.
Audit Metadata