document-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The utility script scripts/scrub_metadata.py utilizes subprocess.run to invoke the SetFile command on macOS. This functionality is used to reset filesystem dates as part of a thorough metadata scrubbing workflow. The command implementation uses a structured argument list and hardcoded formatting for the date string, which effectively prevents shell injection vulnerabilities.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves extracting content from external PDF documents using libraries like pdfplumber and Camelot, which creates an ingestion surface for untrusted data. Ingestion points: PDF files processed via extraction patterns defined in references/pdf-extraction-patterns.md. Boundary markers: The provided extraction templates do not explicitly implement delimiters or specific warnings to ignore instructions embedded in the extracted text. Capability inventory: The skill has access to Bash, Write, and Read tools, and includes scripts that execute system commands. Sanitization: No specific content sanitization or escaping mechanisms are documented for the text extracted before it is returned to the agent context.
  • [EXTERNAL_DOWNLOADS]: The skill references and integrates several widely-used and established libraries and services, including pypdf, pdfplumber, ReportLab, Playwright, Mistral OCR, and IBM's Docling project for document extraction and processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — document-pdf