venue-templates
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text to customize LaTeX templates and inspects external PDF files, which constitutes a surface for indirect prompt injection.
- Ingestion points:
scripts/customize_template.pyingests user-provided arguments for--title,--authors, and--affiliations.scripts/validate_format.pyingests PDF files for inspection. - Boundary markers: No specific delimiters or warnings for embedded instructions are present in the processing scripts.
- Capability inventory:
scripts/customize_template.pyhas file-writing capabilities (open(path, 'w')).scripts/validate_format.pyhas command execution capabilities viasubprocess.runto call PDF inspection tools. - Sanitization: The
customize_template.pyscript performs direct regex substitution of user strings into LaTeX files without explicit sanitization for LaTeX special characters or commands. - [COMMAND_EXECUTION]: The script
scripts/validate_format.pyexecutes external system commands using thesubprocessmodule. - Evidence: The script calls
pdfinfoandpdffonts(part of the Poppler utility suite) to extract metadata and font information from PDF files. - Risk Mitigation: The implementation uses list-based arguments in
subprocess.run()and does not useshell=True, which effectively mitigates common shell injection vectors.
Audit Metadata