arxiv-submission

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The arxiv_preflight.py script processes content from a user-specified directory, reading LaTeX files to detect potentially private comments or specific keywords (e.g., 'TODO', 'reviewer', 'confidential').
  • Ingestion points: The script uses Path.rglob("*") to iterate through all files in a provided directory and reads their content using read_text().
  • Boundary markers: The script does not use specific delimiters but performs static analysis using regular expressions on the file content.
  • Capability inventory: The script is restricted to reading local files and writing reports to standard output (stdout/JSON). It does not perform network operations, subprocess executions, or file modifications.
  • Sanitization: The script uses character replacement (errors="replace") when reading files to handle non-UTF-8 content safely.
  • [EXTERNAL_DOWNLOADS]: The documentation recommends the use of arxiv-latex-cleaner, a utility developed by Google Research, which can be installed via a standard package manager. This is a well-known tool from a recognized organization used for its intended purpose of stripping comments from TeX source.
  • [COMMAND_EXECUTION]: The documentation provides standard instructions for users to run local LaTeX compilation (latexmk) and the provided preflight script. These commands are informational and intended for manual execution by the user in their local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — arxiv-submission