paper-three-pass-extraction

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a recipe for data acquisition that uses the Bash tool to run mkdir and curl commands. These commands incorporate variables like {pdf_url}, {output_root}, and {paper_slug} sourced from external paper records. Constructing shell commands with untrusted input can lead to command injection or path traversal if the calling agent does not implement strict sanitization of the placeholders.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted academic papers, creating a vulnerability surface for indirect prompt injection.
  • Ingestion points: Untrusted content enters the agent's context through PDFs fetched via curl and HTML fetched via WebFetch from external URLs.
  • Boundary markers: The instructions lack requirements for the agent to use delimiters or ignore-embedded-instruction markers when processing the text of the papers.
  • Capability inventory: The agent possesses powerful capabilities including Bash (shell access), Read (file system access), and WebFetch (network access).
  • Sanitization: There are no instructions to sanitize or validate the content of the academic papers before the agent performs its multi-pass analysis.
  • [EXTERNAL_DOWNLOADS]: The workflow relies on fetching documents from external URLs. While the skill includes fallback logic for well-known services like PubMed, the primary download source is an arbitrary {pdf_url} from a user-provided record, allowing the agent to interact with potentially untrusted external infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — paper-three-pass-extraction