document-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The utility script
scripts/scrub_metadata.pyutilizessubprocess.runto invoke theSetFilecommand on macOS. This functionality is used to reset filesystem dates as part of a thorough metadata scrubbing workflow. The command implementation uses a structured argument list and hardcoded formatting for the date string, which effectively prevents shell injection vulnerabilities. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves extracting content from external PDF documents using libraries like
pdfplumberandCamelot, which creates an ingestion surface for untrusted data. Ingestion points: PDF files processed via extraction patterns defined inreferences/pdf-extraction-patterns.md. Boundary markers: The provided extraction templates do not explicitly implement delimiters or specific warnings to ignore instructions embedded in the extracted text. Capability inventory: The skill has access toBash,Write, andReadtools, and includes scripts that execute system commands. Sanitization: No specific content sanitization or escaping mechanisms are documented for the text extracted before it is returned to the agent context. - [EXTERNAL_DOWNLOADS]: The skill references and integrates several widely-used and established libraries and services, including
pypdf,pdfplumber,ReportLab,Playwright,Mistral OCR, and IBM'sDoclingproject for document extraction and processing.
Audit Metadata