nutrient-document-processing

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an MCP server hosted on the official NPM registry and documentation from a well-known document processing service (Nutrient). These are legitimate resources and are handled according to standard practices.
  • [COMMAND_EXECUTION]: The skill provides example curl commands for interacting with the Nutrient API and instructions for running an official MCP server via npx. These commands are standard for the described purpose of document processing and do not involve suspicious execution patterns.
  • [DATA_EXPOSURE_&_EXFILTRATION]: While the skill involves sending documents to a remote API (api.nutrient.io), this is the primary purpose of the tool. The instructions correctly advise the user to manage their API key via environment variables, which is a safe practice. There is no evidence of unauthorized data exfiltration or access to sensitive local files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — nutrient-document-processing