pdf-processing

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install well-known Python libraries, specifically pdfplumber and pypdf, which are industry standards for PDF manipulation.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it extracts content from external PDF files that could contain malicious instructions for the agent.
  • Ingestion points: PDF extraction using pdfplumber in SKILL.md.
  • Boundary markers: None identified in the provided instructions.
  • Capability inventory: The skill performs file system read and write operations.
  • Sanitization: No sanitization or validation of the extracted document content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 01:19 PM
Security Audit — agent-trust-hub — pdf-processing