corpus-report

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The run.sh script contains a command to download and execute the uv installer from Astral's official site (astral.sh). Astral is a well-known technology provider, and this is the standard installation method for the tool.
  • [COMMAND_EXECUTION]: The skill uses Bash scripts (run.sh, sanity.sh) to manage the Python virtual environment and orchestrate the execution of the reporting tool.
  • [PROMPT_INJECTION]: The skill processes metadata and logs from a PDF extraction corpus, which serves as a potential surface for indirect prompt injection if the processed data contains malicious instructions.
  • Ingestion points: Reads from metadata/manifest.jsonl, metadata/pattern_registry.json, and results/*/timings_summary.json (documented in manifest.py and timings.py).
  • Boundary markers: No explicit delimiter or 'ignore' instructions are used when passing aggregated data to the agent context.
  • Capability inventory: The skill has access to the Bash and Read tools and can pass aggregated data to the create-figure skill for visualization.
  • Sanitization: Data is strictly parsed using the standard json library, which ensures the content adheres to expected structures before being processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — corpus-report