syncfusion-dotnet-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and utilizes official Syncfusion NuGet packages, such as
Syncfusion.Pdf.Net.Core,Syncfusion.Pdf.Imaging.Net.Core, andSyncfusion.PDF.OCR.Net.Core. These are legitimate libraries from a well-known software vendor used for document processing. - [COMMAND_EXECUTION]: The skill uses
dotnet-scriptto execute temporary.csxfiles (Mode 2). This is a core architectural design of the skill to perform PDF operations without modifying the user's primary project files. The instructions include a rule to delete these temporary scripts immediately after execution to maintain environment cleanliness. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it can extract text and metadata from externally provided PDF documents (e.g., from local storage or cloud providers like AWS S3 and Azure Blob). However, the risk is inherent to the document processing use case and the skill uses standard library APIs for extraction.
- [SAFE]: Network operations described in the reference snippets (Azure, AWS, Google Drive, Dropbox) are standard integrations for document storage and retrieval. They use official SDKs and represent expected functionality for a PDF processing library.
Audit Metadata