corpus-report
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
run.shscript contains a command to download and execute theuvinstaller from Astral's official site (astral.sh). Astral is a well-known technology provider, and this is the standard installation method for the tool. - [COMMAND_EXECUTION]: The skill uses Bash scripts (
run.sh,sanity.sh) to manage the Python virtual environment and orchestrate the execution of the reporting tool. - [PROMPT_INJECTION]: The skill processes metadata and logs from a PDF extraction corpus, which serves as a potential surface for indirect prompt injection if the processed data contains malicious instructions.
- Ingestion points: Reads from
metadata/manifest.jsonl,metadata/pattern_registry.json, andresults/*/timings_summary.json(documented inmanifest.pyandtimings.py). - Boundary markers: No explicit delimiter or 'ignore' instructions are used when passing aggregated data to the agent context.
- Capability inventory: The skill has access to the
BashandReadtools and can pass aggregated data to thecreate-figureskill for visualization. - Sanitization: Data is strictly parsed using the standard
jsonlibrary, which ensures the content adheres to expected structures before being processed.
Audit Metadata