NYC

translate-pdf

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No instructions attempting to override agent behavior or bypass safety filters were detected in the metadata or markdown instructions.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials, sensitive file path access, or unauthorized network operations were found. The skill operates entirely on local files.
  • [Obfuscation] (SAFE): No hidden content, encoded strings, or malicious unicode characters were present in the source code.
  • [Unverifiable Dependencies] (SAFE): The skill depends on the standard and well-known pymupdf library for PDF processing.
  • [Indirect Prompt Injection] (SAFE): While the skill processes untrusted PDF documents, the risk is negligible as it lacks high-risk capabilities like network access or arbitrary code execution based on file content.
  • Ingestion points: input.pdf (processed in scripts/extract_texts.py).
  • Boundary markers: Delimiters are not explicitly used, but the workflow provides manual oversight during translation.
  • Capability inventory: Local file system access for reading and writing PDF files via the pymupdf library.
  • Sanitization: Standard JSON parsing is used for translation mappings.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:18 PM