syncfusion-wpf-pdf-viewer
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides an AI agent with methods to extract text, form data, and annotation content from PDF files. This exposes an attack surface for indirect prompt injection, where malicious instructions could be embedded in document data to influence the agent's behavior.
- Ingestion points: Methods found in
references/extract-text-from-pdf.md(e.g.,ExtractText) andreferences/form-filling.md. - Boundary markers: The provided code snippets do not include delimiters or instructions for the agent to ignore potentially malicious content within the PDF.
- Capability inventory: The generated code includes sensitive operations such as file system writes (
pdfViewer.Save), printing (pdfViewer.Print), and process execution (System.Diagnostics.Process.Start). - Sanitization: No sanitization or validation logic is provided in the samples to vet data retrieved from PDF files before usage.
- [COMMAND_EXECUTION]: A code reference in
references/annotation.mddemonstrates usingSystem.Diagnostics.Process.Start(filePath)inside aFileLinkAnnotationClickedevent handler. This pattern allows the resulting application to launch external processes or open URLs based on content defined within a PDF document's link annotations.
Audit Metadata