nutrient-document-processing
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill suggests installing an MCP server using
npx -y @nutrient-sdk/dws-mcp-server. This command downloads and executes a package from the public NPM registry. - [COMMAND_EXECUTION]: The documentation provides multiple
curlcommands intended for execution in the terminal to interact with the document processing API. - [DATA_EXFILTRATION]: By design, the skill sends local document files (PDF, DOCX, images, etc.) to the Nutrient API (
api.nutrient.io) for processing. Document data is transmitted to a third-party service as part of the intended functionality. - [PROMPT_INJECTION]: The skill processes untrusted document data, creating a surface for indirect prompt injection if the agent interprets content within those documents as instructions.
- Ingestion points: Processes local files (e.g., PDF, DOCX, HTML) provided as input via
curlmultipart requests. - Boundary markers: Absent. There are no instructions for the agent to distinguish between its system guidelines and content extracted from processed files.
- Capability inventory: Shell command execution via
curland file system access for reading inputs and writing outputs. - Sanitization: No explicit sanitization or validation of the content extracted from processed documents is described.
Audit Metadata