sci-figure

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external PDF documents and extracts caption text, which could contain malicious instructions designed to influence the agent's behavior during downstream processing. Evidence: Ingestion occurs in sci_figure/caption_detector.py via pdfplumber; No explicit boundary markers or instructions to ignore embedded content are used; The skill has file system write capabilities via ImageProcessor; Extracted text is not sanitized for prompt injection patterns.
  • [OBFUSCATION]: The README_CN.md file contains non-printable control characters such as U+0008 (Backspace), U+000C (Form Feed), and U+0007 (Bell) embedded within commands and descriptions (e.g., ash, igure). These appear to be unintentional artifacts from text encoding or copy-pasting rather than malicious obfuscation attempts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:16 PM
Security Audit — agent-trust-hub — sci-figure