visa-doc-translate

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted text content from user-provided images (e.g., passports, bank statements), creating a vector for indirect prompt injection.
  • Ingestion points: The skill ingests user-provided images via the /visa-doc-translate command as specified in SKILL.md.
  • Boundary markers: There are no instructions for the agent to use delimiters or ignore instructions potentially embedded within the OCR-extracted text.
  • Capability inventory: The skill possesses significant capabilities including shell command execution (pip, brew, sips), file system writing, and Python script execution.
  • Sanitization: The instructions do not define any sanitization or validation procedures for the text extracted from documents before it is translated or placed into the final PDF.
  • [COMMAND_EXECUTION]: The skill automatically executes shell commands and package managers to prepare its environment.
  • Evidence: SKILL.md instructs the agent to run pip install for multiple libraries and brew install tesseract. It also uses the native macOS sips utility for image conversion.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes runtime script generation and execution to produce output.
  • Evidence: The instructions in SKILL.md require the agent to "Create a Python script using PIL and reportlab libraries" and subsequently "Execute the script to generate the PDF."
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — visa-doc-translate