fact-extractor
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted text from external books and transcripts. While it uses delimiters to define the extraction scope, adversarial content within the source text could attempt to manipulate the LLM's behavior. \n
- Ingestion points: The skill reads input text provided via the
chapterandextractcommands infact_extractor/cli.py. \n - Boundary markers: Uses
<context_before>,<primary_text>, and<context_after>tags in the model prompt to scope the processing area. \n - Capability inventory: The skill can write JSONL artifacts to the local file system and perform network requests to an LLM proxy via
aiohttp. \n - Sanitization: Implements strict validation of the LLM output, including JSON shape checks, exact quote grounding verification, and vocabulary enforcement for the factuality field. \n- [COMMAND_EXECUTION]: The skill performs automated directory cleanup using
shutil.rmtreewhen the--forceflag is specified for thestage-bookorextractcommands. This capability, intended for artifact management, poses a risk if target paths are not constrained to the skill's workspace.
Audit Metadata