Read, create, edit, merge, split, rotate, fill, render, and verify workspace PDF files. Use whenever the requested input or deliverable is a .pdf, including extracting text or tables, inspecting metadata and page geometry, generating a new PDF, rearranging pages, filling AcroForm fields, or checking visual layout. Do not use for Google Drive or browser-only PDF workflows.
80
100%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
Outsider-authored free text can enter the LLM context because the skill’s runtime `inspect` workflow extracts page text/tables/fields from the user-provided PDF (`page.extract_text(...)` in `scripts/pdf_cli.py`) and then writes those extracted strings into JSON outputs (`--text-out`, `--tables-out`) which the agent may subsequently load and include in its own LLM context; the tool does not restrict/escape/allowlist the extracted prose beyond truncating `textPreview` (and it can also emit full `--text-out`).
c88d7d1
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.