How to review suspicious PDFs before AI use
Last reviewed: August 30, 2026 · Editor: Prompt Injection Check
A PDF can contain selectable text, images, annotations, links, and hidden layers. A normal-looking page is not proof that its contents are safe for an AI workflow.
Review without executing content
- Open the file in a patched viewer and avoid enabling embedded actions or macros.
- Check the sender, filename, links, and requested business action.
- Extract a redacted text sample for review; do not upload secrets.
- Scan the text for override, extraction, exfiltration, or hidden-content warnings.
- Inspect images and screenshots separately because text-only tools cannot see them.
Scenario: a fake invoice
A PDF invoice may include an instruction to change bank details or send a copy of internal records. Treat that sentence as document content. Verify payment details through a trusted channel and require human approval.
What the scanner cannot inspect
Prompt Injection Check does not render pasted HTML or analyze PDF structure, attachments, images, or active content. Use endpoint protection and document-safety controls for those layers.