arxiv-submission
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
arxiv_preflight.pyscript processes content from a user-specified directory, reading LaTeX files to detect potentially private comments or specific keywords (e.g., 'TODO', 'reviewer', 'confidential'). - Ingestion points: The script uses
Path.rglob("*")to iterate through all files in a provided directory and reads their content usingread_text(). - Boundary markers: The script does not use specific delimiters but performs static analysis using regular expressions on the file content.
- Capability inventory: The script is restricted to reading local files and writing reports to standard output (stdout/JSON). It does not perform network operations, subprocess executions, or file modifications.
- Sanitization: The script uses character replacement (
errors="replace") when reading files to handle non-UTF-8 content safely. - [EXTERNAL_DOWNLOADS]: The documentation recommends the use of
arxiv-latex-cleaner, a utility developed by Google Research, which can be installed via a standard package manager. This is a well-known tool from a recognized organization used for its intended purpose of stripping comments from TeX source. - [COMMAND_EXECUTION]: The documentation provides standard instructions for users to run local LaTeX compilation (
latexmk) and the provided preflight script. These commands are informational and intended for manual execution by the user in their local environment.
Audit Metadata