book-workshop

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external, untrusted sources including PDF files, Word documents (.doc/.docx), and web URLs. This creates a surface for indirect prompt injection where instructions hidden within the source text could attempt to influence the agent's behavior during the conversion or layout process.\n- Ingestion points: The intake bench utilizes markitright for PDFs, textutil for Word documents, and WebFetch for URLs to convert content to markdown.\n- Boundary markers: The skill establishes a 'markdown master' as a single source of truth to separate the content layer from the design and rendering logic.\n- Capability inventory: The pipeline includes capabilities to render PDF outputs using Paged.js and CSS, as well as specialized layout tasks.\n- Sanitization: The skill incorporates a text-fidelity verification step where extracted text is diffed against an independent second source (e.g., vatican.va) to detect errors or malicious alterations during the intake process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:17 PM