sci-html

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting and processing untrusted external files (PDFs, Markdown, and JSON).
  • Ingestion points: User-provided documents are read and parsed in parser.py and paper_pipeline.py.
  • Boundary markers: The skill does not use specific delimiters to isolate extracted content from the processing logic.
  • Capability inventory: The skill performs local file system writes to create the deck output directory and writes extracted metadata to JSON files.
  • Sanitization: The rendering engine in renderer.py correctly applies html.escape() to all user-derived strings before they are embedded in the final HTML slides, preventing stored cross-site scripting (XSS) in the generated artifacts.
  • [SAFE]: Comprehensive analysis of the source code and metadata revealed no evidence of malicious patterns, prompt injections, or obfuscated content. The skill operates as intended for academic document conversion without performing unauthorized network operations or privilege escalation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:16 PM
Security Audit — agent-trust-hub — sci-html