AGENT LAB: SKILLS
skills/smithery/ai/pdf/Gen Agent Trust Hub

pdf

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Prompt Injection (LOW): This skill is vulnerable to Indirect Prompt Injection (Category 8) due to its primary function of processing external data.
  • Ingestion points: Untrusted data enters the agent context via PdfReader, pdfplumber.open, and pytesseract.image_to_string as shown in SKILL.md.
  • Boundary markers: Absent. The instructions do not specify delimiters or warnings for the agent to ignore instructions embedded within the extracted text/tables.
  • Capability inventory: The skill instructions involve file writing (writer.write, df.to_excel, c.save) and command-line execution (qpdf, pdftk, pdftotext).
  • Sanitization: Absent. Extracted text is processed or printed directly without validation or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:05 PM