doc2qra

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses the uvx tool in text_handler.py and pdf_handler.py to download and execute code from remote sources, including the author's own repository (github.com/grahama1970/treesitter-tools.git) and the well-known marker-pdf package.
  • [COMMAND_EXECUTION]: Multiple modules use subprocess.run to call CLI utilities such as memory-agent, pkill, curl, and marker_single. Some arguments are derived from user-provided file paths.
  • [EXTERNAL_DOWNLOADS]: url_handler.py uses httpx and curl to fetch content from user-provided URLs for distillation.
  • [PROMPT_INJECTION]: The skill processes untrusted document content and interpolates it into LLM prompts, creating a surface for indirect prompt injection. Ingestion points: cli.py (file, URL, and text inputs). Boundary markers: Newline delimiters used in qra_prompts.py. Capability inventory: subprocess.run (CLI calls) and httpx.get (Network). Sanitization: Text is truncated but not specifically sanitized to prevent instruction leakage.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — doc2qra