doc2qra
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses the
uvxtool intext_handler.pyandpdf_handler.pyto download and execute code from remote sources, including the author's own repository (github.com/grahama1970/treesitter-tools.git) and the well-knownmarker-pdfpackage. - [COMMAND_EXECUTION]: Multiple modules use
subprocess.runto call CLI utilities such asmemory-agent,pkill,curl, andmarker_single. Some arguments are derived from user-provided file paths. - [EXTERNAL_DOWNLOADS]:
url_handler.pyuseshttpxandcurlto fetch content from user-provided URLs for distillation. - [PROMPT_INJECTION]: The skill processes untrusted document content and interpolates it into LLM prompts, creating a surface for indirect prompt injection. Ingestion points:
cli.py(file, URL, and text inputs). Boundary markers: Newline delimiters used inqra_prompts.py. Capability inventory:subprocess.run(CLI calls) andhttpx.get(Network). Sanitization: Text is truncated but not specifically sanitized to prevent instruction leakage.
Audit Metadata