nutrient-document-processing

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and extracts text from external documents (PDF, DOCX, HTML, and images) using OCR and text extraction tools, which allows untrusted content to enter the agent's reasoning context.
  • Ingestion points: Local files like document.pdf, scanned.pdf, and index.html processed in SKILL.md.
  • Boundary markers: Absent; there are no instructions or delimiters to isolate extracted text or warn the agent about embedded instructions.
  • Capability inventory: Performs network POST requests via curl to an external API.
  • Sanitization: Absent; the skill does not define methods for filtering or validating the content extracted from processed documents.
  • [REMOTE_CODE_EXECUTION]: Fetches and runs the @nutrient-sdk/dws-mcp-server package from the official npm registry using npx for tool integration.
  • [DATA_EXFILTRATION]: Transmits the contents of local documents to the Nutrient DWS API at api.nutrient.io to perform requested operations such as conversion and OCR.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — nutrient-document-processing