nutrient-document-processing

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: The skill uses curl to upload local files (PDF, DOCX, XLSX, etc.) to https://api.nutrient.io/build for processing. While this is the intended primary purpose of the skill, it involves sending potentially sensitive local data to an external API endpoint.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to use npx -y @nutrient-sdk/dws-mcp-server, which downloads and executes the Nutrient DWS MCP server package from the npm registry at runtime.
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands including curl for API interaction and npx for package execution to perform document operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Untrusted documents (PDF, DOCX, HTML, etc.) are read from the local file system and sent to the Nutrient API via curl in SKILL.md.
  • Boundary markers: None identified; processed documents are not wrapped in delimiters or safety instructions in the provided examples.
  • Capability inventory: The skill uses curl for network requests and npx for executing code (as seen in SKILL.md).
  • Sanitization: No sanitization or validation of the input document content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM