paper-poster-html
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided academic paper source files (LaTeX or PDF) to extract text, equations, and figures. This data enters the agent's context during content planning and automated review phases. A maliciously crafted paper could attempt to inject instructions to influence the agent's behavior during these loops.
- Ingestion points: Paper source ingestion in Phase 1 (
SKILL.md). - Boundary markers: Present. The skill mandates fresh threads for content audits (
mcp__codex__codex) and directs models to review file paths rather than inline summaries. - Capability inventory: Subprocess execution and file system writes are present across the gate scripts.
- Sanitization: The skill relies on cross-model auditing to verify the fidelity of extracted claims against the source paper.
- [EXTERNAL_DOWNLOADS]: The skill fetches assets from well-known external sources to support its primary functionality. It downloads the MathJax library from the jsDelivr CDN (
https://cdn.jsdelivr.net/npm/mathjax@3/es5/tex-svg.js) for local rendering of mathematical formulas. It also uses web search and fetch tools to retrieve current poster specifications from official conference domains. - [COMMAND_EXECUTION]: The orchestration script (
scripts/run_gates.py) and PDF verification module (scripts/_posterly/verify_final.py) utilize thesubprocessmodule to execute internal Python scripts and system utilities likepdfinfo. The implementation uses list-based command construction with resolved absolute paths to mitigate potential shell injection vulnerabilities.
Audit Metadata