fact-extractor

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted text from external books and transcripts. While it uses delimiters to define the extraction scope, adversarial content within the source text could attempt to manipulate the LLM's behavior. \n
  • Ingestion points: The skill reads input text provided via the chapter and extract commands in fact_extractor/cli.py. \n
  • Boundary markers: Uses <context_before>, <primary_text>, and <context_after> tags in the model prompt to scope the processing area. \n
  • Capability inventory: The skill can write JSONL artifacts to the local file system and perform network requests to an LLM proxy via aiohttp. \n
  • Sanitization: Implements strict validation of the LLM output, including JSON shape checks, exact quote grounding verification, and vocabulary enforcement for the factuality field. \n- [COMMAND_EXECUTION]: The skill performs automated directory cleanup using shutil.rmtree when the --force flag is specified for the stage-book or extract commands. This capability, intended for artifact management, poses a risk if target paths are not constrained to the skill's workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — fact-extractor