ingest-doc
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates its pipeline by executing bash scripts located in sibling directories using subprocess.run. It dynamically constructs these paths based on the skill's installation directory.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests untrusted data from documents or URLs and passes them to downstream LLM-based processing stages.
- Ingestion points: The ingest command in ingest_compliance.py accepts external file paths and URLs as input.
- Boundary markers: No delimiters or safety instructions are implemented to isolate the document content from the processing logic.
- Capability inventory: The skill executes external scripts and modifies environment variables like PYTHONPATH to include local skill directories.
- Sanitization: No sanitization or validation is performed on the content of the ingested documents or the provided URLs.
Audit Metadata