lossless-doc-compress

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs file read and write operations on the local filesystem to process documents and save results (compressed document, removal log, and scorecard). These actions are limited to the working directory and support the core functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an inherent attack surface by ingesting external documents via text, links, or file paths. It mitigates this risk with explicit instructions in SKILL.md and fidelity-rules.md to treat input content as untrusted evidence and ignore any embedded directives. 1. Ingestion points: Document input provided via pasted body, link, or file path. 2. Boundary markers: Present. Instructions explicitly mandate treating document content as evidence, not directives. 3. Capability inventory: File reading and writing (log, scorecard, compressed document). 4. Sanitization: Semantic instruction provided to the agent to ignore any embedded commands within processed documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 02:44 PM
Security Audit — agent-trust-hub — lossless-doc-compress