nutrient-document-processing
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DATA_EXFILTRATION]: The skill uses
curlto upload local files (PDF, DOCX, XLSX, etc.) tohttps://api.nutrient.io/buildfor processing. While this is the intended primary purpose of the skill, it involves sending potentially sensitive local data to an external API endpoint. - [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to use
npx -y @nutrient-sdk/dws-mcp-server, which downloads and executes the Nutrient DWS MCP server package from the npm registry at runtime. - [COMMAND_EXECUTION]: The skill utilizes several shell commands including
curlfor API interaction andnpxfor package execution to perform document operations. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Untrusted documents (PDF, DOCX, HTML, etc.) are read from the local file system and sent to the Nutrient API via
curlinSKILL.md. - Boundary markers: None identified; processed documents are not wrapped in delimiters or safety instructions in the provided examples.
- Capability inventory: The skill uses
curlfor network requests andnpxfor executing code (as seen inSKILL.md). - Sanitization: No sanitization or validation of the input document content is performed before processing.
Audit Metadata