pdf-analysis
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWPROMPT_INJECTIONNO_CODE
Full Analysis
- PROMPT_INJECTION (LOW): The skill possesses an indirect prompt injection surface. Because the skill's purpose is to ingest and analyze external PDF files, an attacker could embed malicious instructions within a document to hijack the agent's behavior. 1. Ingestion points: User-provided PDF files for academic and technical analysis. 2. Boundary markers: Absent; there are no instructions to the agent on how to differentiate between document content and system instructions. 3. Capability inventory: Content extraction, summarization, and article generation (using the
create-articlecommand). 4. Sanitization: Absent; no validation or filtering of PDF content is specified. - NO_CODE (SAFE): The skill consists exclusively of Markdown documentation and templates. No scripts, binaries, or automated installation procedures were detected.
Audit Metadata