distill
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches content from user-provided URLs and utilizes
uvxto retrieve thetreesitter-toolsutility from the vendor's GitHub repository. It also downloads well-known PDF extraction tools such aspymupdf4llmandmarker-pdfif they are not already installed. - [REMOTE_CODE_EXECUTION]: The script uses
uvxto dynamically run tools fetched from remote sources, specifically thetreesitter-toolsutility from the vendor's repository (github.com/grahama1970) andmarker-pdffor enhanced PDF processing. - [COMMAND_EXECUTION]: The skill executes shell commands via
subprocess.runto interact with PDF extraction tools, code symbol analyzers, and thememory-agentfor data storage. It includes a custom function to stream long-running subprocess output to the terminal for monitoring. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external URLs and PDF files and includes it in prompts sent to the LLM for knowledge extraction, creating a vulnerability surface for indirect prompt injection.
- Ingestion points:
fetch_url()andread_file()functions indistill.pywhich load content from external sources. - Boundary markers: The system prompt uses a 'Text:' label for content but does not employ strong delimiters or explicit instructions for the LLM to ignore potentially malicious embedded instructions.
- Capability inventory: The skill possesses the ability to execute shell commands (
subprocess.run), perform network requests (urllib.request), and write to the local file system. - Sanitization: Extracted content is not sanitized or filtered for prompt injection patterns before being interpolated into LLM requests.
Audit Metadata