visa-doc-translate
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted text content from user-provided images (e.g., passports, bank statements), creating a vector for indirect prompt injection.
- Ingestion points: The skill ingests user-provided images via the
/visa-doc-translatecommand as specified in SKILL.md. - Boundary markers: There are no instructions for the agent to use delimiters or ignore instructions potentially embedded within the OCR-extracted text.
- Capability inventory: The skill possesses significant capabilities including shell command execution (
pip,brew,sips), file system writing, and Python script execution. - Sanitization: The instructions do not define any sanitization or validation procedures for the text extracted from documents before it is translated or placed into the final PDF.
- [COMMAND_EXECUTION]: The skill automatically executes shell commands and package managers to prepare its environment.
- Evidence: SKILL.md instructs the agent to run
pip installfor multiple libraries andbrew install tesseract. It also uses the native macOSsipsutility for image conversion. - [REMOTE_CODE_EXECUTION]: The skill utilizes runtime script generation and execution to produce output.
- Evidence: The instructions in SKILL.md require the agent to "Create a Python script using PIL and reportlab libraries" and subsequently "Execute the script to generate the PDF."
Audit Metadata