pdf-tools
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation provides instructions for executing various command-line utilities and local scripts for PDF processing.
- Evidence: Calls to
qpdf,ghostscript(gs),verapdf, andpoppler-utils(pdftotext) are documented inreferences/legacy-utilities.mdandreferences/batch-and-accessibility.md. - Evidence: The form-filling workflow in
references/form-filling.mdreferences a suite of local Python scripts (e.g.,extract_form_field_info.py,fill_fillable_fields.py) for automated document manipulation. - [INDIRECT_PROMPT_INJECTION]: The skill uses LLMs and vision models to extract data from PDFs, which creates an inherent attack surface for instructions embedded within processed documents.
- Ingestion points: The
extractInvoiceandextractComplexTablefunctions inreferences/ai-extraction-patterns.mdingest raw text and images extracted from PDFs. - Boundary markers: Not explicitly shown in the prompt snippets, though the instructions recommend directing the AI to specific high-value pages.
- Capability inventory: The skill has capabilities to write files (
fs.writeFile,doc.save) and execute subprocesses (python scripts/...,qpdf,gs) as part of its document processing pipelines. - Sanitization: The skill demonstrates a strong pattern of using Zod schemas to enforce structured output and validate data extracted by AI models, reducing the risk of accidental instruction following.
Audit Metadata