pdf-harvester
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to extract text from external, untrusted sources (PDF files and URLs) and prepare it for ingestion into a RAG system. The provided extraction logic does not include sanitization or boundary markers for the extracted text.
- Ingestion points: The
harvest_pdfandharvest_pdf_urlfunctions inSKILL.mdingest data from local file paths and remote URLs. - Boundary markers: The extraction methods (Method 1, 2, and 3) and chunking strategies do not wrap the extracted text in delimiters or include instructions to ignore embedded commands.
- Capability inventory: The skill utilizes file system access (
pdfplumber,fitz), OCR capabilities (pytesseract), and network requests (httpx). - Sanitization: There is no evidence of text sanitization or filtering to remove potential malicious instructions embedded within PDF text before it is passed to the
ingestfunction. - [EXTERNAL_DOWNLOADS]: The
harvest_pdf_urlfunction implementation inSKILL.mduses thehttpxlibrary to download files from arbitrary URLs. While this is consistent with the skill's documented purpose of harvesting PDFs, it represents a network interaction with untrusted remote servers where the retrieved content is immediately processed by the extraction engine.
Audit Metadata