pdf-processing
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install well-known Python libraries, specifically
pdfplumberandpypdf, which are industry standards for PDF manipulation. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it extracts content from external PDF files that could contain malicious instructions for the agent.
- Ingestion points: PDF extraction using
pdfplumberinSKILL.md. - Boundary markers: None identified in the provided instructions.
- Capability inventory: The skill performs file system read and write operations.
- Sanitization: No sanitization or validation of the extracted document content is mentioned.
Audit Metadata