odl-pdf

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes diagnostic scripts (detect-env.sh, hybrid-health.sh) to assess the local environment and verify tool operation. These scripts perform standard reconnaissance for the legitimate purpose of ensuring the tool is correctly configured.\n- [EXTERNAL_DOWNLOADS]: The skill documentation provides instructions for installing dependencies from official package registries. Additionally, the hybrid-health.sh script uses curl or wget to verify server availability, incorporating regex validation to prevent URL-based security issues.\n- [PROMPT_INJECTION]: The instruction set includes strong defensive measures against indirect prompt injection by explicitly telling the agent to treat all extracted PDF content as untrusted data and to never interpret it as instructions or commands.\n- [SAFE]: The skill implements a 'human-in-the-loop' design, requiring the agent to request user approval for environment mutations or network requests. It also emphasizes using the installed tool's own help output as the primary source of truth, minimizing the risk of outdated or incorrect command generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 04:31 AM
Security Audit — agent-trust-hub — odl-pdf