liteparse

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements local document parsing using the 'liteparse' library (version 2.0.0). All documented workflows focus on local processing without cloud dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill references standard installation procedures for well-known and trusted tools:
  • Python package 'liteparse' from PyPI.
  • Node.js package '@llamaindex/liteparse' from npm.
  • System dependencies including LibreOffice, ImageMagick, and Tesseract via standard package managers (brew, apt-get, choco).
  • [COMMAND_EXECUTION]: The CLI tool 'lit' and the 'batch_parse_dir.py' script perform legitimate file system operations (reading documents, writing text/JSON outputs) and call system binaries (LibreOffice's 'soffice', ImageMagick's 'convert') required for its primary purpose of document conversion and parsing.
  • [DATA_EXFILTRATION]: While the skill mentions an optional --ocr-server-url for HTTP-based OCR, this is presented as a user-configurable feature for custom infrastructure rather than a hardcoded exfiltration path. Standard usage remains local.
  • [PROMPT_INJECTION]: No prompt injection or behavior override patterns were found in the instructions or metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a data ingestion surface (parsing untrusted PDFs/Office files). It is classified as safe because it returns raw text/JSON data for further processing rather than executing instructions contained within the documents, and it includes clear agent operating procedures for validating results.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — liteparse