sci-figure
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external PDF documents and extracts caption text, which could contain malicious instructions designed to influence the agent's behavior during downstream processing. Evidence: Ingestion occurs in
sci_figure/caption_detector.pyviapdfplumber; No explicit boundary markers or instructions to ignore embedded content are used; The skill has file system write capabilities viaImageProcessor; Extracted text is not sanitized for prompt injection patterns. - [OBFUSCATION]: The
README_CN.mdfile contains non-printable control characters such as U+0008 (Backspace), U+000C (Form Feed), and U+0007 (Bell) embedded within commands and descriptions (e.g.,ash,igure). These appear to be unintentional artifacts from text encoding or copy-pasting rather than malicious obfuscation attempts.
Audit Metadata