pdf-brain-ingest
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external PDF, Markdown, and TXT files that are processed by an LLM for summarization and classification. Maliciously crafted documents could potentially contain instructions aimed at influencing the generated summaries or metadata.\n
- Ingestion points: Untrusted data enters the pipeline through document files processed by the
joelclaw docs addcommand.\n - Boundary markers: No explicit boundary markers or 'ignore' instructions are documented for the LLM processing stages.\n
- Capability inventory: The skill has capabilities for file system access (NAS), external command execution, and network-based book acquisition.\n
- Sanitization: No specific sanitization or filtering of the extracted text is mentioned prior to LLM processing.\n- [COMMAND_EXECUTION]: The skill makes extensive use of the
joelclawCLI and external processing tools likeopendataloader-pdfandollamato perform indexing, search, and system monitoring. These commands are required for the skill's primary function of managing a document library.\n- [EXTERNAL_DOWNLOADS]: The acquisition workflow (aa-book) includes functionality to download books from external sources based on search queries or specific hashes to expand the document library.
Audit Metadata