nutrient-document-processing

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill suggests installing an MCP server using npx -y @nutrient-sdk/dws-mcp-server. This command downloads and executes a package from the public NPM registry.
  • [COMMAND_EXECUTION]: The documentation provides multiple curl commands intended for execution in the terminal to interact with the document processing API.
  • [DATA_EXFILTRATION]: By design, the skill sends local document files (PDF, DOCX, images, etc.) to the Nutrient API (api.nutrient.io) for processing. Document data is transmitted to a third-party service as part of the intended functionality.
  • [PROMPT_INJECTION]: The skill processes untrusted document data, creating a surface for indirect prompt injection if the agent interprets content within those documents as instructions.
  • Ingestion points: Processes local files (e.g., PDF, DOCX, HTML) provided as input via curl multipart requests.
  • Boundary markers: Absent. There are no instructions for the agent to distinguish between its system guidelines and content extracted from processed files.
  • Capability inventory: Shell command execution via curl and file system access for reading inputs and writing outputs.
  • Sanitization: No explicit sanitization or validation of the content extracted from processed documents is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — nutrient-document-processing