skills/crazynomad/skills/doc-mindmap/Gen Agent Trust Hub

doc-mindmap

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user documents and uses a local LLM to generate summaries and classification labels. These labels are directly used to create directory structures and symbolic links on the filesystem without sanitization. A malicious document could potentially influence the LLM to output path traversal sequences, causing the script to create symbolic links in unintended locations.\n
  • Ingestion points: The DocConverter class in scripts/doc_converter.py reads file content during scanning and summarization tasks.\n
  • Boundary markers: The prompts for the LLM lack explicit instructions to disregard potentially malicious directives embedded within the input documents.\n
  • Capability inventory: The script possesses the capability to create directories (os.makedirs) and symbolic links (os.symlink) based on the strings generated by the AI model.\n
  • Sanitization: There is no evidence of validation or sanitization for the classification labels (topic, usage, client) or suggested filenames returned by the LLM before they are used in path-joining and file system operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 10:06 PM
Security Audit — agent-trust-hub — doc-mindmap