Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands for environment setup and PDF processing.
- Evidence: Use of
uv pip install,python3 -m pip install,brew install,sudo apt-get install, andpdftoppminSKILL.md. - [PRIVILEGE_ESCALATION]: The skill requests administrative privileges to install system-level utilities.
- Evidence:
sudo apt-get install -y poppler-utilsinSKILL.md. This is a standard procedure for installing the well-known Poppler rendering tool on Debian-based systems. - [INDIRECT_PROMPT_INJECTION]: The skill processes external PDF files, which represents an attack surface for indirect prompt injection if the ingested content contains instructions designed to influence the agent.
- Ingestion points:
pdfplumberandpypdfare used to extract text and data from PDF files. - Boundary markers: No specific delimiters or instructions to ignore embedded content are provided.
- Capability inventory: The skill has capabilities for shell command execution (
pdftoppm), file system writes (output/pdf/), and package installation. - Sanitization: No explicit sanitization or validation of extracted text is described.
Audit Metadata