skills/grahama1970/fetcher/distill/Gen Agent Trust Hub

distill

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from user-provided URLs and utilizes uvx to retrieve the treesitter-tools utility from the vendor's GitHub repository. It also downloads well-known PDF extraction tools such as pymupdf4llm and marker-pdf if they are not already installed.
  • [REMOTE_CODE_EXECUTION]: The script uses uvx to dynamically run tools fetched from remote sources, specifically the treesitter-tools utility from the vendor's repository (github.com/grahama1970) and marker-pdf for enhanced PDF processing.
  • [COMMAND_EXECUTION]: The skill executes shell commands via subprocess.run to interact with PDF extraction tools, code symbol analyzers, and the memory-agent for data storage. It includes a custom function to stream long-running subprocess output to the terminal for monitoring.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external URLs and PDF files and includes it in prompts sent to the LLM for knowledge extraction, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: fetch_url() and read_file() functions in distill.py which load content from external sources.
  • Boundary markers: The system prompt uses a 'Text:' label for content but does not employ strong delimiters or explicit instructions for the LLM to ignore potentially malicious embedded instructions.
  • Capability inventory: The skill possesses the ability to execute shell commands (subprocess.run), perform network requests (urllib.request), and write to the local file system.
  • Sanitization: Extracted content is not sanitized or filtered for prompt injection patterns before being interpolated into LLM requests.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 05:23 AM
Security Audit — agent-trust-hub — distill