doc-mindmap
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user documents and uses a local LLM to generate summaries and classification labels. These labels are directly used to create directory structures and symbolic links on the filesystem without sanitization. A malicious document could potentially influence the LLM to output path traversal sequences, causing the script to create symbolic links in unintended locations.\n
- Ingestion points: The
DocConverterclass inscripts/doc_converter.pyreads file content during scanning and summarization tasks.\n - Boundary markers: The prompts for the LLM lack explicit instructions to disregard potentially malicious directives embedded within the input documents.\n
- Capability inventory: The script possesses the capability to create directories (
os.makedirs) and symbolic links (os.symlink) based on the strings generated by the AI model.\n - Sanitization: There is no evidence of validation or sanitization for the classification labels (
topic,usage,client) or suggested filenames returned by the LLM before they are used in path-joining and file system operations.
Audit Metadata