extract-controls

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The entry point run.sh executes several shell commands and sources environment variables from a .env file located in a path defined by the MEMORY_ROOT environment variable.
  • Evidence: source "$MEMORY_ROOT/.env" and various uv run python calls in run.sh.
  • [DATA_EXPOSURE]: The skill is designed to handle sensitive credentials like ARANGO_PASSWORD by sourcing them from environment variables and .env files. While it instructs users not to hardcode them, the loading process itself makes these credentials available in the process environment.
  • Evidence: SKILL.md environment variable table and run.sh sourcing logic.
  • [DYNAMIC_EXECUTION]: The script extract_controls.py uses sys.path manipulation to load Python modules from paths constructed using environment variables (MEMORY_ROOT) and hardcoded user home subdirectories (~/.pi/skills). This allows for dynamic code loading from locations that might be modified by other processes or users.
  • Evidence: _sys.path.insert(0, str(_Path.home() / ".pi" / "skills")) and sys.path.insert(0, _SCRIPTS_PATH) in extract_controls.py.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface (Category 8). It ingests untrusted data from PDF documents and user-supplied strings via the extract command. This data is processed by regex and fuzzy matching tiers, then stored in chunk_control_edges and proof_jobs for further processing by downstream agents (e.g., lean4-prove). A malicious document could attempt to influence these downstream components.
  • Ingestion points: PDF files via run.sh extract <path> and inline text via run.sh extract --text.
  • Boundary markers: None identified in the provided scripts to delimit untrusted document content from instructions.
  • Capability inventory: The skill has file read capabilities (Read tool) and can execute shell commands (Bash tool).
  • Sanitization: No explicit sanitization or escaping of extracted document text was observed before it is used to create graph edges or queue jobs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — extract-controls