Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyimplements runtime monkeypatching by overriding functions in an external library. - The script modifies
pypdf.generic.DictionaryObject.get_inheritedat runtime to change how selection list fields are handled, which is a form of dynamic behavior modification. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract and process text from external PDF documents, which represents an attack surface for indirect instructions.
- Ingestion points: Text and table extraction via
pypdf,pdfplumber,pypdfium2, andpytesseract(SKILL.md, reference.md). - Boundary markers: The instructions do not specify boundary markers or delimiters to separate extracted document content from the agent's instructions.
- Capability inventory: The skill includes extensive capabilities for filesystem interaction, including reading, writing, and executing command-line utilities (SKILL.md, reference.md).
- Sanitization: There is no evidence of sanitization or filtering of extracted text to prevent embedded instructions from influencing the agent's behavior.
- [COMMAND_EXECUTION]: The skill provides instructions and examples for executing several binary command-line tools.
- Documented tools include
qpdf,pdftotext,pdftk, andpdfimages, which perform operations directly on the host system's filesystem.
Audit Metadata