paper-compile
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (LaTeX source files, BibTeX files, and generated compilation logs) to diagnose errors and verify page counts. A malicious LaTeX file could produce specific error messages or PDF content designed to hijack the agent's logic during the parsing and auto-fix loop.
- Ingestion points: The agent reads content from
$PAPER_DIR/main.tex,references.bib, and the generatedcompile.logfile in Step 3 and Step 6. - Boundary markers: No specific boundary markers or instructions to ignore embedded commands are present in the prompts used to interpret file contents.
- Capability inventory: The skill has high capabilities including
Bash(*)for command execution andWrite/Editfor file system modification. - Sanitization: There is no evidence of sanitization or filtering of the content read from LaTeX files or logs before it is processed by the agent's logic.
- [DYNAMIC_EXECUTION]: The skill utilizes a dynamic execution pattern in Step 6 to verify page counts.
- Evidence: The workflow uses a piped command `pdftotext main.pdf
- | python3 -c "..."` to execute a multi-line Python script for text analysis. While the script itself is a hardcoded template, it operates directly on the output of a file generated from user-provided LaTeX source.
Audit Metadata