latex-tables

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill instructs the agent to use sudo for package management tasks, specifically sudo tlmgr install tabularray and sudo tlmgr update --self --all. These commands grant the agent elevated access to modify the system-wide TeX distribution.\n- [COMMAND_EXECUTION]: The skill utilizes shell commands such as kpsewhich and tlmgr to manage and verify the LaTeX environment.\n- [PROMPT_INJECTION]: A 'Self-Evolving Skill' directive in SKILL.md instructs the agent to 'fix this file immediately' if errors occur or workarounds are needed. This permits the agent to overwrite its own operational instructions, creating a risk that malicious or incorrect logic could be persisted within the skill.\n- [INDIRECT_PROMPT_INJECTION]: The self-evolution mechanism creates a vulnerability surface for instruction poisoning.\n
  • Ingestion points: System error messages and user-provided LaTeX code that necessitates a 'workaround' (SKILL.md).\n
  • Boundary markers: Absent; there are no delimiters or warnings to prevent the agent from adopting instructions embedded in failing inputs.\n
  • Capability inventory: The skill is granted Edit and Bash permissions, enabling it to modify its own files and execute shell commands.\n
  • Sanitization: The skill lacks instructions for sanitizing content before the agent uses it to update the skill's instructions.\n- [EXTERNAL_DOWNLOADS]: The skill fetches the tabularray package and updates from the official TeX Live repository using the tlmgr utility.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 06:56 AM
Security Audit — agent-trust-hub — latex-tables