mat-synthesis-extraction

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Python script (scripts/parse_pdfs.py) to extract text from PDFs. The script uses argparse to define input and output paths and performs standard file read/write operations within the local environment.
  • [PROMPT_INJECTION]: The skill processes untrusted PDF content, creating an indirect prompt injection surface.
  • Ingestion points: Text extracted from PDFs is used as input for LLM prompts defined in SKILL.md.
  • Boundary markers: Prompt templates use standard textual labels without robust delimiters to separate data from instructions.
  • Capability inventory: The process involves reading local files and writing extracted data to JSON files.
  • Sanitization: There is no evidence of filtering or escaping of the extracted PDF text before processing.
  • [SAFE]: No malicious patterns such as hardcoded credentials, network exfiltration, or obfuscated code were found. The skill operates according to its documented purpose for scientific research automation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:47 PM