ingest-compliance-doc

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it processes untrusted data (PDFs and URLs) through LLM-based sub-skills (e.g., doc2qra). An attacker could embed malicious instructions within a compliance document to influence the agent's behavior during extraction or storage stages.
  • Ingestion points: The path argument in the ingest and batch commands in ingest_compliance.py accepts both local file paths and remote URLs.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are used when passing extracted content to subsequent stages.
  • Capability inventory: The skill uses subprocess.run to execute bash scripts for multiple sub-skills (extractor, cui-marker, doc2qra, taxonomy, memory). It also declares run_command and read_file in its allowed-tools.
  • Sanitization: The script performs a basic check for file existence for local paths but does not sanitize or validate the content of the documents or the URLs before processing.
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run to chain local scripts. While it uses the recommended list format for arguments which prevents standard shell injection, the passed path or preset arguments could potentially be interpreted as flags by the underlying sub-scripts if they are not strictly validated within those scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ingest-compliance-doc