latex-posters
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input at multiple stages: user-defined prompts for schematic generation and external PDF files for quality review. In
scripts/generate_schematic_ai.py, user prompts are interpolated into larger instructional templates without formal sanitization, relying on basic formatting rather than robust boundary markers. The skill's capabilities include executing local scripts, performing file system writes, and making network requests to the OpenRouter API, which creates a surface where malicious instructions could potentially influence the agent. - [COMMAND_EXECUTION]: The skill utilizes
subprocess.runinscripts/generate_schematic.pyand shell commands inscripts/review_poster.shto execute local utilities likepdfinfo,pdffonts, andgs. While these calls are structured using argument lists to mitigate common command injection vulnerabilities, the execution of system-level tools based on external parameters constitutes a managed security surface.
Audit Metadata