pdf-brain-ingest

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external PDF, Markdown, and TXT files that are processed by an LLM for summarization and classification. Maliciously crafted documents could potentially contain instructions aimed at influencing the generated summaries or metadata.\n
  • Ingestion points: Untrusted data enters the pipeline through document files processed by the joelclaw docs add command.\n
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are documented for the LLM processing stages.\n
  • Capability inventory: The skill has capabilities for file system access (NAS), external command execution, and network-based book acquisition.\n
  • Sanitization: No specific sanitization or filtering of the extracted text is mentioned prior to LLM processing.\n- [COMMAND_EXECUTION]: The skill makes extensive use of the joelclaw CLI and external processing tools like opendataloader-pdf and ollama to perform indexing, search, and system monitoring. These commands are required for the skill's primary function of managing a document library.\n- [EXTERNAL_DOWNLOADS]: The acquisition workflow (aa-book) includes functionality to download books from external sources based on search queries or specific hashes to expand the document library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — pdf-brain-ingest