culture-index

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute local Python scripts using the uv tool to process Culture Index PDF files and extract behavioral trait data.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes system-level dependencies including poppler and tesseract for PDF rendering and Optical Character Recognition (OCR) functionality.
  • [PROMPT_INJECTION]: The skill ingests untrusted external data from PDFs and interview transcripts, which creates an attack surface for indirect prompt injection. \n- Ingestion points: PDF files processed via extract_pdf.py and interview transcripts analyzed via the predict-from-interview.md workflow. \n- Boundary markers: The instructions do not explicitly define boundary markers or delimiters to protect against malicious instructions embedded in the processed data. \n- Capability inventory: The agent is instructed to execute shell commands and perform file operations as part of the data extraction and report generation process. \n- Sanitization: Data extraction from PDFs is constrained by OCR and OpenCV logic which targets specific visual coordinates, while transcript analysis relies on LLM-based behavioral pattern matching.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:12 PM
Security Audit — agent-trust-hub — culture-index