portable-document-handler

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/fill_fillable_fields.py redefines the get_inherited method of the pypdf.generic.DictionaryObject class at runtime. This dynamic modification (monkeypatching) is used to address a specific formatting bug in the library's selection list handling.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external, untrusted PDF files through text extraction and rendering, creating a surface where malicious instructions could potentially influence the agent. * Ingestion points: scripts/extract_form_field_info.py, scripts/convert_pdf_to_images.py, and pypdf / pdfplumber snippets. * Boundary markers: None; there are no instructions for the agent to delimit or ignore content within PDF documents. * Capability inventory: Broad capabilities including filesystem writing (via pypdf writers) and shell command execution (via qpdf and poppler-utils). * Sanitization: No sanitization or validation of extracted PDF content is provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:00 PM
Security Audit — agent-trust-hub — portable-document-handler