syncfusion-dotnet-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes official Syncfusion NuGet packages, such as Syncfusion.Pdf.Net.Core, Syncfusion.Pdf.Imaging.Net.Core, and Syncfusion.PDF.OCR.Net.Core. These are legitimate libraries from a well-known software vendor used for document processing.
  • [COMMAND_EXECUTION]: The skill uses dotnet-script to execute temporary .csx files (Mode 2). This is a core architectural design of the skill to perform PDF operations without modifying the user's primary project files. The instructions include a rule to delete these temporary scripts immediately after execution to maintain environment cleanliness.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it can extract text and metadata from externally provided PDF documents (e.g., from local storage or cloud providers like AWS S3 and Azure Blob). However, the risk is inherent to the document processing use case and the skill uses standard library APIs for extraction.
  • [SAFE]: Network operations described in the reference snippets (Azure, AWS, Google Drive, Dropbox) are standard integrations for document storage and retrieval. They use official SDKs and represent expected functionality for a PDF processing library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:27 PM
Security Audit — agent-trust-hub — syncfusion-dotnet-pdf