document-ai
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external document data (PDFs, images) through AI models, which creates a surface for indirect prompt injection attacks.
- Ingestion points: Data enters the context through functions like
extractFromPDF,processInvoiceBatch, andprocessWithUnstructuredwhich ingest content from local file paths. - Boundary markers: The implementation patterns include delimiters and instructions such as "Extract information according to this JSON schema" and "Return ONLY valid JSON" to guide model output.
- Capability inventory: The code snippets utilize
fs.readFileSyncfor file access and perform network requests to AI providers (Anthropic, OpenAI, Unstructured, Upstash). - Sanitization: The skill demonstrates best practices by using the Zod library in the "Invoice Extraction" pattern to validate and sanitize model outputs against a strict schema.
- [COMMAND_EXECUTION]: The provided implementation patterns use standard Node.js
fsandpathmodules to interact with the local filesystem for reading documents. - [EXTERNAL_DOWNLOADS]: The reference files document several third-party dependencies required for implementation, including
@anthropic-ai/sdk,pdf-to-img,zod,openai,@upstash/vector,llamaindex, andunstructured-client. All identified packages are well-known, legitimate libraries for document processing and AI service integration.
Audit Metadata