latex-setup
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructions direct the agent to use
sudofor administrative tasks, specifically installing system packages viaapton Linux andtlmgron macOS. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for processing untrusted data.
- Ingestion points: Content is read from user-provided
.texfiles in Step 2 to extract document classes and required packages. - Boundary markers: Absent. The skill does not provide instructions to delimit or ignore potentially malicious content within the LaTeX files.
- Capability inventory: The skill has the capability to execute shell commands, install system-wide packages via
sudo, and run local compilers. - Sanitization: Absent. There are no validation steps to ensure that extracted package names or configuration settings are safe before being used in shell commands.
- [COMMAND_EXECUTION]: The skill uses various shell commands for environment detection (
which,pdflatex --version), package management (tlmgr install), and multi-stage document compilation pipelines. - [DYNAMIC_EXECUTION]: The skill references the
write18feature in Step 5. If shell-escape (write18) is enabled during compilation, the LaTeX compiler can execute arbitrary shell commands defined within the document. Processing a malicious or untrusted.texfile with this feature enabled could result in unauthorized command execution on the host system. - [EXTERNAL_DOWNLOADS]: The skill encourages the agent to download venue-specific templates from external web sources. While the instructions specify official sources, this pattern involves fetching and processing remote content that could be spoofed or compromised.
Audit Metadata