paper-compile

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (LaTeX source files, BibTeX files, and generated compilation logs) to diagnose errors and verify page counts. A malicious LaTeX file could produce specific error messages or PDF content designed to hijack the agent's logic during the parsing and auto-fix loop.
  • Ingestion points: The agent reads content from $PAPER_DIR/main.tex, references.bib, and the generated compile.log file in Step 3 and Step 6.
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present in the prompts used to interpret file contents.
  • Capability inventory: The skill has high capabilities including Bash(*) for command execution and Write/Edit for file system modification.
  • Sanitization: There is no evidence of sanitization or filtering of the content read from LaTeX files or logs before it is processed by the agent's logic.
  • [DYNAMIC_EXECUTION]: The skill utilizes a dynamic execution pattern in Step 6 to verify page counts.
  • Evidence: The workflow uses a piped command `pdftotext main.pdf
  • | python3 -c "..."` to execute a multi-line Python script for text analysis. While the script itself is a hardcoded template, it operates directly on the output of a file generated from user-provided LaTeX source.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — paper-compile