venue-templates

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text to customize LaTeX templates and inspects external PDF files, which constitutes a surface for indirect prompt injection.
  • Ingestion points: scripts/customize_template.py ingests user-provided arguments for --title, --authors, and --affiliations. scripts/validate_format.py ingests PDF files for inspection.
  • Boundary markers: No specific delimiters or warnings for embedded instructions are present in the processing scripts.
  • Capability inventory: scripts/customize_template.py has file-writing capabilities (open(path, 'w')). scripts/validate_format.py has command execution capabilities via subprocess.run to call PDF inspection tools.
  • Sanitization: The customize_template.py script performs direct regex substitution of user strings into LaTeX files without explicit sanitization for LaTeX special characters or commands.
  • [COMMAND_EXECUTION]: The script scripts/validate_format.py executes external system commands using the subprocess module.
  • Evidence: The script calls pdfinfo and pdffonts (part of the Poppler utility suite) to extract metadata and font information from PDF files.
  • Risk Mitigation: The implementation uses list-based arguments in subprocess.run() and does not use shell=True, which effectively mitigates common shell injection vectors.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — venue-templates