doc2math

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes technical documents provided by the user, which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: Document input in Step 1.
  • Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or block quotes) to isolate the input document.
  • Capability inventory: The skill is limited to generating a JSON object; it does not contain scripts or commands for file access, network operations, or subprocess execution.
  • Sanitization: The 'Zero-Inference Protocol' mandates that every extracted element must cite an exact source phrase, mitigating the risk of the agent following instructions embedded in the data.
  • [EXTERNAL_DOWNLOADS]: The skill provides links to external resources for the project.
  • Evidence: References a GitHub repository and a hosted application on a third-party platform (up.railway.app).
  • [METADATA_POISONING]: The skill metadata contains a non-current date.
  • Evidence: The 'date_added' field is set to '2026-05-31'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:45 PM
Security Audit — agent-trust-hub — doc2math