statement-extract-and-prove

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run within its test suite (tests/make_fixtures.py and tests/run_tests.py) to automate data generation and validation.
  • Evidence includes calls to pdftoppm (part of the standard poppler-utils) to rasterize PDF pages for testing scanned-document scenarios.
  • The test runner invokes the skill's own scripts (extract_statement.py and prove.py) using the current Python interpreter.
  • These operations are limited to the testing environment and do not pose a risk during normal skill operation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external PDF files, which represents a potential surface for indirect prompt injection if the agent were to blindly follow instructions embedded in the PDF text.
  • Ingestion points: Untrusted data enters the context via pdfplumber.open() in scripts/extract_statement.py.
  • Boundary markers: The skill uses strict CSV/JSON output formats and emphasizes deterministic parsing, which serves to isolate the data from the agent's instructions.
  • Capability inventory: The skill is limited to local file system writes (CSV, JSON, XLSX) and has no network access or arbitrary shell execution capabilities.
  • Sanitization: Data is validated through regex for dates and decimal.Decimal for currency, with a dedicated prove.py script that verifies arithmetic invariants (opening + sum = closing).
  • The skill's design, which mandates script-based extraction over visual reading, significantly mitigates the risk of an agent being misled by malicious content within a statement.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 12:50 AM
Security Audit — agent-trust-hub — statement-extract-and-prove