mineru-extract
Warn
Audited by Gen Agent Trust Hub on Oct 9, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill takes user-provided URLs and sends them to the third-party service mineru.net for processing. While this is the intended functionality, users should be aware that content from these URLs is shared with an external entity.
- [EXTERNAL_DOWNLOADS]: The scripts scripts/mineru_extract.py and scripts/mineru_parse_documents.py download ZIP archives from a dynamic URL (full_zip_url) returned by the MinerU API response.
- [DYNAMIC_EXECUTION]: Both scripts use zipfile.extractall() to unpack the downloaded ZIP archive into the local workspace. The extractall() method is vulnerable to path traversal attacks (Zip Slip) if the ZIP archive contains entries with parent directory references (..), potentially allowing files to be written outside the intended directory.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs by converting them into Markdown.
- Ingestion points: source_url parameter in both scripts.
- Boundary markers: None present in the Markdown output to delimit external content from instructions.
- Capability inventory: File system write access via extraction and network access via urllib.request.
- Sanitization: Basic filename sanitization is performed, but the content of the extracted Markdown is not sanitized.
Audit Metadata