skills/fcakyon/phd-skills/latex-setup/Gen Agent Trust Hub

latex-setup

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructions direct the agent to use sudo for administrative tasks, specifically installing system packages via apt on Linux and tlmgr on macOS.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for processing untrusted data.
  • Ingestion points: Content is read from user-provided .tex files in Step 2 to extract document classes and required packages.
  • Boundary markers: Absent. The skill does not provide instructions to delimit or ignore potentially malicious content within the LaTeX files.
  • Capability inventory: The skill has the capability to execute shell commands, install system-wide packages via sudo, and run local compilers.
  • Sanitization: Absent. There are no validation steps to ensure that extracted package names or configuration settings are safe before being used in shell commands.
  • [COMMAND_EXECUTION]: The skill uses various shell commands for environment detection (which, pdflatex --version), package management (tlmgr install), and multi-stage document compilation pipelines.
  • [DYNAMIC_EXECUTION]: The skill references the write18 feature in Step 5. If shell-escape (write18) is enabled during compilation, the LaTeX compiler can execute arbitrary shell commands defined within the document. Processing a malicious or untrusted .tex file with this feature enabled could result in unauthorized command execution on the host system.
  • [EXTERNAL_DOWNLOADS]: The skill encourages the agent to download venue-specific templates from external web sources. While the instructions specify official sources, this pattern involves fetching and processing remote content that could be spoofed or compromised.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 04:18 PM