syncfusion-winforms-pdf-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides APIs and templates for extracting text from PDF pages (references/extract-text.md). This creates an attack surface for indirect prompt injection, where an attacker could embed malicious instructions in a PDF file. If the agent extracts and processes this text without proper delimitation or sanitization, it could be tricked into executing unintended actions.
- Ingestion points: pdfDocumentView.ExtractText in references/extract-text.md.
- Boundary markers: Absent; extracted text is concatenated directly into strings without markers.
- Capability inventory: System.Diagnostics.Process.Start (Command Execution), LoadedDocument.Save (File system access), Print (IO).
- Sanitization: No sanitization or validation of extracted text is recommended in the snippets.
- [COMMAND_EXECUTION]: The documentation for hyperlink navigation in references/navigation.md demonstrates the use of System.Diagnostics.Process.Start() to open URIs. While this is a common practice for opening a web browser, this API can be used to execute arbitrary shell commands or open sensitive local files if a malicious URI (e.g., a file path or a crafted shell command string) is processed.
Audit Metadata