ingest-compliance-doc
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection because it processes untrusted data (PDFs and URLs) through LLM-based sub-skills (e.g., doc2qra). An attacker could embed malicious instructions within a compliance document to influence the agent's behavior during extraction or storage stages.
- Ingestion points: The
pathargument in theingestandbatchcommands iningest_compliance.pyaccepts both local file paths and remote URLs. - Boundary markers: No explicit boundary markers or 'ignore' instructions are used when passing extracted content to subsequent stages.
- Capability inventory: The skill uses
subprocess.runto execute bash scripts for multiple sub-skills (extractor,cui-marker,doc2qra,taxonomy,memory). It also declaresrun_commandandread_filein its allowed-tools. - Sanitization: The script performs a basic check for file existence for local paths but does not sanitize or validate the content of the documents or the URLs before processing.
- [COMMAND_EXECUTION]: The skill makes extensive use of
subprocess.runto chain local scripts. While it uses the recommended list format for arguments which prevents standard shell injection, the passedpathorpresetarguments could potentially be interpreted as flags by the underlying sub-scripts if they are not strictly validated within those scripts.
Audit Metadata