portable-document-handler
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
scripts/fill_fillable_fields.pyredefines theget_inheritedmethod of thepypdf.generic.DictionaryObjectclass at runtime. This dynamic modification (monkeypatching) is used to address a specific formatting bug in the library's selection list handling. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external, untrusted PDF files through text extraction and rendering, creating a surface where malicious instructions could potentially influence the agent. * Ingestion points:
scripts/extract_form_field_info.py,scripts/convert_pdf_to_images.py, andpypdf/pdfplumbersnippets. * Boundary markers: None; there are no instructions for the agent to delimit or ignore content within PDF documents. * Capability inventory: Broad capabilities including filesystem writing (viapypdfwriters) and shell command execution (viaqpdfandpoppler-utils). * Sanitization: No sanitization or validation of extracted PDF content is provided.
Audit Metadata