document-chat-interface

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from diverse external sources, such as public web pages, GitHub repositories, and PDF documents. This content is directly interpolated into prompts for the Large Language Model (e.g., in the follow-up question generation and RAG chat loops) without adequate security guardrails.
  • Ingestion points: The skill handles data from PDFs, Web URLs, GitHub repositories, and email archives via the examples/document_processors.py module.
  • Capability inventory: The skill possesses network capabilities (via requests), file system access (open), and generates responses using LLM calls.
  • Boundary markers: The provided prompt templates lack explicit delimiters or instructions to ignore potential instructions embedded within the document context.
  • Sanitization: While basic text cleaning is provided, there is no logic to detect or neutralize malicious instructions hidden within the analyzed documents.
  • [DATA_EXFILTRATION]: The extract_email_content function in examples/document_processors.py allows the agent to read and return all files within a directory path provided at runtime. If not strictly restricted, this could be directed towards sensitive system directories to expose configuration files or credentials to the LLM context.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external sources including the GitHub API and web URLs. These operations are consistent with the skill's stated purpose and utilize well-known services.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — document-chat-interface