tesseract-ocr
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted image data through OCR, creating a surface for indirect prompt injection where text within images could be interpreted as instructions.
- Ingestion points: Image files such as
input.pngmentioned inSKILL.mdare processed by thetesseracttool. - Boundary markers: No delimiters or specific instructions are provided to separate the extracted OCR text from agent instructions.
- Capability inventory: The skill performs local CLI execution of
tesseractandrg(ripgrep). - Sanitization:
SKILL.mdidentifies basic Unicode and whitespace normalization in the post-processing phase. - [EXTERNAL_DOWNLOADS]: The skill references documentation and code from official Tesseract OCR repositories.
- Evidence: URL references to
https://github.com/tesseract-ocr/tessdocandhttps://github.com/tesseract-ocr/tesseractlocated inreferences/tesseract-ocr-2026-02-18.md.
Audit Metadata