extractor-quality-check

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run and subprocess.Popen to execute shell commands. This includes running the extraction pipeline in extraction.py, executing automated remediation jobs in remediation.py based on externally generated issue codes, and calling various CLI tools to gather system state.
  • [EXTERNAL_DOWNLOADS]: The skill communicates with external AI services to perform document analysis and validation. It uses the scillm proxy and has been observed interacting with llm.chutes.ai for teacher-based evaluation and prompt preflight checks.
  • [CREDENTIALS_UNSAFE]: The scripts _teacher.py and teacher_preflight.py contain a hardcoded development API key (sk-dev-proxy-123) that is used as a fallback if the required environment variables are missing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — extractor-quality-check