paper-three-pass-extraction
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a recipe for data acquisition that uses the
Bashtool to runmkdirandcurlcommands. These commands incorporate variables like{pdf_url},{output_root}, and{paper_slug}sourced from external paper records. Constructing shell commands with untrusted input can lead to command injection or path traversal if the calling agent does not implement strict sanitization of the placeholders. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted academic papers, creating a vulnerability surface for indirect prompt injection.
- Ingestion points: Untrusted content enters the agent's context through PDFs fetched via
curland HTML fetched viaWebFetchfrom external URLs. - Boundary markers: The instructions lack requirements for the agent to use delimiters or ignore-embedded-instruction markers when processing the text of the papers.
- Capability inventory: The agent possesses powerful capabilities including
Bash(shell access),Read(file system access), andWebFetch(network access). - Sanitization: There are no instructions to sanitize or validate the content of the academic papers before the agent performs its multi-pass analysis.
- [EXTERNAL_DOWNLOADS]: The workflow relies on fetching documents from external URLs. While the skill includes fallback logic for well-known services like PubMed, the primary download source is an arbitrary
{pdf_url}from a user-provided record, allowing the agent to interact with potentially untrusted external infrastructure.
Audit Metadata