doc2math
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes technical documents provided by the user, which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Document input in Step 1.
- Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or block quotes) to isolate the input document.
- Capability inventory: The skill is limited to generating a JSON object; it does not contain scripts or commands for file access, network operations, or subprocess execution.
- Sanitization: The 'Zero-Inference Protocol' mandates that every extracted element must cite an exact source phrase, mitigating the risk of the agent following instructions embedded in the data.
- [EXTERNAL_DOWNLOADS]: The skill provides links to external resources for the project.
- Evidence: References a GitHub repository and a hosted application on a third-party platform (up.railway.app).
- [METADATA_POISONING]: The skill metadata contains a non-current date.
- Evidence: The 'date_added' field is set to '2026-05-31'.
Audit Metadata