extract-tables

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Code obfuscation is present in src/python/parsers/lattice_backend.py, where the function name morphological_open_image is partially encoded using hex escape sequences (\x6d\x6f\x72\x70\x68).
  • [REMOTE_CODE_EXECUTION]: The skill uses dynamic module loading and execution in run.sh and conftest.py, constructing Python script strings and executing them via python3 -c and importlib utilities.
  • [COMMAND_EXECUTION]: The skill frequently invokes external tools through subprocess.run, including mypyc for compilation, python3 for sanity checks, and scillm for VLM title inference, found in src/python/build_parsers.py, src/python/title_extractor.py, and sanity/scillm_vlm.py.
  • [DATA_EXFILTRATION]: Document content, including extracted text and page screenshots, is transmitted to external VLM backends for processing in src/python/evidence_matrix.py and src/python/title_extractor.py.
  • [PROMPT_INJECTION]: An indirect prompt injection surface exists because the skill processes untrusted PDF content and interpolates it into prompts sent to secondary AI models (VLM), creating a risk that malicious document content could influence the agent's behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — extract-tables