statement-extract-and-prove
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runwithin its test suite (tests/make_fixtures.pyandtests/run_tests.py) to automate data generation and validation. - Evidence includes calls to
pdftoppm(part of the standard poppler-utils) to rasterize PDF pages for testing scanned-document scenarios. - The test runner invokes the skill's own scripts (
extract_statement.pyandprove.py) using the current Python interpreter. - These operations are limited to the testing environment and do not pose a risk during normal skill operation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external PDF files, which represents a potential surface for indirect prompt injection if the agent were to blindly follow instructions embedded in the PDF text.
- Ingestion points: Untrusted data enters the context via
pdfplumber.open()inscripts/extract_statement.py. - Boundary markers: The skill uses strict CSV/JSON output formats and emphasizes deterministic parsing, which serves to isolate the data from the agent's instructions.
- Capability inventory: The skill is limited to local file system writes (CSV, JSON, XLSX) and has no network access or arbitrary shell execution capabilities.
- Sanitization: Data is validated through regex for dates and
decimal.Decimalfor currency, with a dedicatedprove.pyscript that verifies arithmetic invariants (opening + sum = closing). - The skill's design, which mandates script-based extraction over visual reading, significantly mitigates the risk of an agent being misled by malicious content within a statement.
Audit Metadata