book-workshop
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external, untrusted sources including PDF files, Word documents (.doc/.docx), and web URLs. This creates a surface for indirect prompt injection where instructions hidden within the source text could attempt to influence the agent's behavior during the conversion or layout process.\n- Ingestion points: The intake bench utilizes
markitrightfor PDFs,textutilfor Word documents, andWebFetchfor URLs to convert content to markdown.\n- Boundary markers: The skill establishes a 'markdown master' as a single source of truth to separate the content layer from the design and rendering logic.\n- Capability inventory: The pipeline includes capabilities to render PDF outputs using Paged.js and CSS, as well as specialized layout tasks.\n- Sanitization: The skill incorporates a text-fidelity verification step where extracted text is diffed against an independent second source (e.g., vatican.va) to detect errors or malicious alterations during the intake process.
Audit Metadata