sci-ppt
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
pdflatexandpdftoppmusingsubprocess.runinsrc/aut_sci_ppt/generator/formula_renderer.pyto render mathematical formulas into high-definition images. The implementation mitigates risk by using the-no-shell-escapeflag, which prevents LaTeX from executing arbitrary shell commands. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
https://latex.codecogs.comas a fallback for rendering LaTeX formulas into PNG images insrc/aut_sci_ppt/generator/formula_renderer.py. CodeCogs is a widely recognized service for this specific utility. - [INDIRECT_PROMPT_INJECTION]: The skill parses content from PDF files and structured text which represents a potential attack surface for indirect prompt injection.
- Ingestion points: Text extraction from PDF documents is performed using the
fitz(PyMuPDF) library insrc/aut_sci_ppt/enhanced_agent.py. - Boundary markers: The processing logic does not employ explicit delimiters or system instructions to ignore potential commands embedded in the document text.
- Capability inventory: The skill possesses capabilities for file system modification, network communication, and execution of document processing binaries.
- Sanitization: The skill extracts semantic academic structure but does not specifically sanitize the content for malicious prompt instructions before processing.
- [DYNAMIC_EXECUTION]: The skill utilizes dynamic loading mechanisms for configuration and internal modules.
- In
src/aut_sci_ppt/config.py, it usesimportlibto load shared environment settings from a relative path (../../_shared/env_config.py). - In
src/aut_sci_ppt/paginator/smart_paginator.py,__import__is used to load components from the skill's ownmodelspackage at runtime.
Audit Metadata