nutrient-document-processing

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches and executes the @nutrient-sdk/dws-mcp-server package from the npm registry using npx to provide native tool integration for the agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external documents, creating a potential surface for indirect prompt injection if the documents contain malicious instructions.
  • Ingestion points: Documents in various formats (PDF, DOCX, etc.) are uploaded to the Nutrient API for processing and text extraction.
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions for the agent to ignore content within the processed documents.
  • Capability inventory: The skill can read local files, write output files, and perform network requests to api.nutrient.io.
  • Sanitization: Absent; the raw extracted text and data are returned for agent consumption.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — nutrient-document-processing