extract-controls
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The entry point
run.shexecutes several shell commands and sources environment variables from a.envfile located in a path defined by theMEMORY_ROOTenvironment variable. - Evidence:
source "$MEMORY_ROOT/.env"and variousuv run pythoncalls inrun.sh. - [DATA_EXPOSURE]: The skill is designed to handle sensitive credentials like
ARANGO_PASSWORDby sourcing them from environment variables and.envfiles. While it instructs users not to hardcode them, the loading process itself makes these credentials available in the process environment. - Evidence:
SKILL.mdenvironment variable table andrun.shsourcing logic. - [DYNAMIC_EXECUTION]: The script
extract_controls.pyusessys.pathmanipulation to load Python modules from paths constructed using environment variables (MEMORY_ROOT) and hardcoded user home subdirectories (~/.pi/skills). This allows for dynamic code loading from locations that might be modified by other processes or users. - Evidence:
_sys.path.insert(0, str(_Path.home() / ".pi" / "skills"))andsys.path.insert(0, _SCRIPTS_PATH)inextract_controls.py. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface (Category 8). It ingests untrusted data from PDF documents and user-supplied strings via the
extractcommand. This data is processed by regex and fuzzy matching tiers, then stored inchunk_control_edgesandproof_jobsfor further processing by downstream agents (e.g.,lean4-prove). A malicious document could attempt to influence these downstream components. - Ingestion points: PDF files via
run.sh extract <path>and inline text viarun.sh extract --text. - Boundary markers: None identified in the provided scripts to delimit untrusted document content from instructions.
- Capability inventory: The skill has file read capabilities (
Readtool) and can execute shell commands (Bashtool). - Sanitization: No explicit sanitization or escaping of extracted document text was observed before it is used to create graph edges or queue jobs.
Audit Metadata