ai-pdf-filler-cli
Pass
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
simplicity-clicommand to perform PDF operations. It includes instructions for installing the CLI tool if it's missing usinguvorpip. - [EXTERNAL_DOWNLOADS]: The skill encourages downloading and installing the
ai-pdf-fillerpackage from external repositories (PyPI/uv) to enable its functionality. This package is associated with the skill's author. - [CREDENTIALS_UNSAFE]: The skill instructs users to provide an API key as a command-line argument (
--api-key "<api_key>"). While using placeholders, this pattern can lead to sensitive keys being stored in shell history or process listings. It also mentions a local configuration file~/.config/simplicity-cli/config.jsonfor storing the key. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. * Ingestion points: External data enters the agent context via the
--form-url,--source-url,--context, and--instructionsparameters inSKILL.md. * Boundary markers: There are no explicit boundary markers or instructions to the LLM to ignore embedded commands within the source documents or context strings. * Capability inventory: The skill has the capability to execute shell commands (simplicity-cli) and perform network operations (fetching remote PDFs). * Sanitization: There is no evidence of sanitization or validation of the content provided in the context or fetched from URLs before it is processed by the CLI tool.
Audit Metadata