document-ai

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external document data (PDFs, images) through AI models, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: Data enters the context through functions like extractFromPDF, processInvoiceBatch, and processWithUnstructured which ingest content from local file paths.
  • Boundary markers: The implementation patterns include delimiters and instructions such as "Extract information according to this JSON schema" and "Return ONLY valid JSON" to guide model output.
  • Capability inventory: The code snippets utilize fs.readFileSync for file access and perform network requests to AI providers (Anthropic, OpenAI, Unstructured, Upstash).
  • Sanitization: The skill demonstrates best practices by using the Zod library in the "Invoice Extraction" pattern to validate and sanitize model outputs against a strict schema.
  • [COMMAND_EXECUTION]: The provided implementation patterns use standard Node.js fs and path modules to interact with the local filesystem for reading documents.
  • [EXTERNAL_DOWNLOADS]: The reference files document several third-party dependencies required for implementation, including @anthropic-ai/sdk, pdf-to-img, zod, openai, @upstash/vector, llamaindex, and unstructured-client. All identified packages are well-known, legitimate libraries for document processing and AI service integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 10:15 PM
Security Audit — agent-trust-hub — document-ai