skills/nicepkg/ai-workflow/pdf/Gen Agent Trust Hub

pdf

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/fill_fillable_fields.py implements runtime monkeypatching by overriding functions in an external library.
  • The script modifies pypdf.generic.DictionaryObject.get_inherited at runtime to change how selection list fields are handled, which is a form of dynamic behavior modification.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract and process text from external PDF documents, which represents an attack surface for indirect instructions.
  • Ingestion points: Text and table extraction via pypdf, pdfplumber, pypdfium2, and pytesseract (SKILL.md, reference.md).
  • Boundary markers: The instructions do not specify boundary markers or delimiters to separate extracted document content from the agent's instructions.
  • Capability inventory: The skill includes extensive capabilities for filesystem interaction, including reading, writing, and executing command-line utilities (SKILL.md, reference.md).
  • Sanitization: There is no evidence of sanitization or filtering of extracted text to prevent embedded instructions from influencing the agent's behavior.
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing several binary command-line tools.
  • Documented tools include qpdf, pdftotext, pdftk, and pdfimages, which perform operations directly on the host system's filesystem.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 08:03 AM
Security Audit — agent-trust-hub — pdf