Fail
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: HIGHDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The
examples/invoice-generator.mdfile contains a functiongenerate_invoices_from_csvthat useseval(row['items'])to parse data from a CSV file. This pattern is highly insecure and allows for arbitrary code execution if the CSV file content is controlled by an untrusted source. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external PDF and CSV files (ingestion points in
SKILL.md,scripts/pdf_helper.py, andexamples/invoice-generator.md). The skill lacks boundary markers or sanitization for general text extraction, creating a vulnerability where hidden instructions in documents could be interpreted by the agent as commands. This surface is particularly concerning as the skill also possesses file-writing capabilities across multiple components (e.g.,fitz.Document.save,PdfWriter.write). - [EXTERNAL_DOWNLOADS]: Documentation in
README.mdandreferences/library-installation.mdpoints to external third-party GitHub repositories (github.com/oschwartz10612/poppler-windowsandgithub.com/UB-Mannheim/tesseract) for binary dependencies. While these are standard resources for these specific tools, they represent unmanaged external dependencies.
Recommendations
- AI detected serious security threats
Audit Metadata