mat-synthesis-extraction
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a Python script (
scripts/parse_pdfs.py) to extract text from PDFs. The script usesargparseto define input and output paths and performs standard file read/write operations within the local environment. - [PROMPT_INJECTION]: The skill processes untrusted PDF content, creating an indirect prompt injection surface.
- Ingestion points: Text extracted from PDFs is used as input for LLM prompts defined in
SKILL.md. - Boundary markers: Prompt templates use standard textual labels without robust delimiters to separate data from instructions.
- Capability inventory: The process involves reading local files and writing extracted data to JSON files.
- Sanitization: There is no evidence of filtering or escaping of the extracted PDF text before processing.
- [SAFE]: No malicious patterns such as hardcoded credentials, network exfiltration, or obfuscated code were found. The skill operates according to its documented purpose for scientific research automation.
Audit Metadata