pdf-harvester

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to extract text from external, untrusted sources (PDF files and URLs) and prepare it for ingestion into a RAG system. The provided extraction logic does not include sanitization or boundary markers for the extracted text.
  • Ingestion points: The harvest_pdf and harvest_pdf_url functions in SKILL.md ingest data from local file paths and remote URLs.
  • Boundary markers: The extraction methods (Method 1, 2, and 3) and chunking strategies do not wrap the extracted text in delimiters or include instructions to ignore embedded commands.
  • Capability inventory: The skill utilizes file system access (pdfplumber, fitz), OCR capabilities (pytesseract), and network requests (httpx).
  • Sanitization: There is no evidence of text sanitization or filtering to remove potential malicious instructions embedded within PDF text before it is passed to the ingest function.
  • [EXTERNAL_DOWNLOADS]: The harvest_pdf_url function implementation in SKILL.md uses the httpx library to download files from arbitrary URLs. While this is consistent with the skill's documented purpose of harvesting PDFs, it represents a network interaction with untrusted remote servers where the retrieved content is immediately processed by the extraction engine.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:26 AM