ingest-doc

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates its pipeline by executing bash scripts located in sibling directories using subprocess.run. It dynamically constructs these paths based on the skill's installation directory.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it ingests untrusted data from documents or URLs and passes them to downstream LLM-based processing stages.
  • Ingestion points: The ingest command in ingest_compliance.py accepts external file paths and URLs as input.
  • Boundary markers: No delimiters or safety instructions are implemented to isolate the document content from the processing logic.
  • Capability inventory: The skill executes external scripts and modifies environment variables like PYTHONPATH to include local skill directories.
  • Sanitization: No sanitization or validation is performed on the content of the ingested documents or the provided URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — ingest-doc