nutrient-document-processing
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes and extracts text from external documents (PDF, DOCX, HTML, and images) using OCR and text extraction tools, which allows untrusted content to enter the agent's reasoning context.
- Ingestion points: Local files like
document.pdf,scanned.pdf, andindex.htmlprocessed inSKILL.md. - Boundary markers: Absent; there are no instructions or delimiters to isolate extracted text or warn the agent about embedded instructions.
- Capability inventory: Performs network POST requests via
curlto an external API. - Sanitization: Absent; the skill does not define methods for filtering or validating the content extracted from processed documents.
- [REMOTE_CODE_EXECUTION]: Fetches and runs the
@nutrient-sdk/dws-mcp-serverpackage from the official npm registry usingnpxfor tool integration. - [DATA_EXFILTRATION]: Transmits the contents of local documents to the Nutrient DWS API at
api.nutrient.ioto perform requested operations such as conversion and OCR.
Audit Metadata