culture-index
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute local Python scripts using the
uvtool to process Culture Index PDF files and extract behavioral trait data. - [EXTERNAL_DOWNLOADS]: The skill utilizes system-level dependencies including
popplerandtesseractfor PDF rendering and Optical Character Recognition (OCR) functionality. - [PROMPT_INJECTION]: The skill ingests untrusted external data from PDFs and interview transcripts, which creates an attack surface for indirect prompt injection. \n- Ingestion points: PDF files processed via
extract_pdf.pyand interview transcripts analyzed via thepredict-from-interview.mdworkflow. \n- Boundary markers: The instructions do not explicitly define boundary markers or delimiters to protect against malicious instructions embedded in the processed data. \n- Capability inventory: The agent is instructed to execute shell commands and perform file operations as part of the data extraction and report generation process. \n- Sanitization: Data extraction from PDFs is constrained by OCR and OpenCV logic which targets specific visual coordinates, while transcript analysis relies on LLM-based behavioral pattern matching.
Audit Metadata