sci-html
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting and processing untrusted external files (PDFs, Markdown, and JSON).
- Ingestion points: User-provided documents are read and parsed in
parser.pyandpaper_pipeline.py. - Boundary markers: The skill does not use specific delimiters to isolate extracted content from the processing logic.
- Capability inventory: The skill performs local file system writes to create the deck output directory and writes extracted metadata to JSON files.
- Sanitization: The rendering engine in
renderer.pycorrectly applieshtml.escape()to all user-derived strings before they are embedded in the final HTML slides, preventing stored cross-site scripting (XSS) in the generated artifacts. - [SAFE]: Comprehensive analysis of the source code and metadata revealed no evidence of malicious patterns, prompt injections, or obfuscated content. The skill operates as intended for academic document conversion without performing unauthorized network operations or privilege escalation.
Audit Metadata