extract-tables
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Code obfuscation is present in
src/python/parsers/lattice_backend.py, where the function namemorphological_open_imageis partially encoded using hex escape sequences (\x6d\x6f\x72\x70\x68). - [REMOTE_CODE_EXECUTION]: The skill uses dynamic module loading and execution in
run.shandconftest.py, constructing Python script strings and executing them viapython3 -candimportlibutilities. - [COMMAND_EXECUTION]: The skill frequently invokes external tools through
subprocess.run, includingmypycfor compilation,python3for sanity checks, andscillmfor VLM title inference, found insrc/python/build_parsers.py,src/python/title_extractor.py, andsanity/scillm_vlm.py. - [DATA_EXFILTRATION]: Document content, including extracted text and page screenshots, is transmitted to external VLM backends for processing in
src/python/evidence_matrix.pyandsrc/python/title_extractor.py. - [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill processes untrusted PDF content and interpolates it into prompts sent to secondary AI models (VLM), creating a risk that malicious document content could influence the agent's behavior.
Audit Metadata