NYC

pypdf

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (SAFE): The skill references standard, well-known Python packages (pypdf, reportlab) from the official PyPI registry.
  • [INDIRECT_PROMPT_INJECTION] (LOW): The skill facilitates the extraction of text from PDF documents, creating a potential vector for indirect prompt injection if the source data is untrusted and passed to an LLM without sanitization. 1. Ingestion points: PdfReader.pages[].extract_text() in README.md. 2. Boundary markers: Absent in provided examples. 3. Capability inventory: PdfWriter.write (file write) and text printing. 4. Sanitization: Absent in the provided snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:10 PM