paper-poster-html

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided academic paper source files (LaTeX or PDF) to extract text, equations, and figures. This data enters the agent's context during content planning and automated review phases. A maliciously crafted paper could attempt to inject instructions to influence the agent's behavior during these loops.
  • Ingestion points: Paper source ingestion in Phase 1 (SKILL.md).
  • Boundary markers: Present. The skill mandates fresh threads for content audits (mcp__codex__codex) and directs models to review file paths rather than inline summaries.
  • Capability inventory: Subprocess execution and file system writes are present across the gate scripts.
  • Sanitization: The skill relies on cross-model auditing to verify the fidelity of extracted claims against the source paper.
  • [EXTERNAL_DOWNLOADS]: The skill fetches assets from well-known external sources to support its primary functionality. It downloads the MathJax library from the jsDelivr CDN (https://cdn.jsdelivr.net/npm/mathjax@3/es5/tex-svg.js) for local rendering of mathematical formulas. It also uses web search and fetch tools to retrieve current poster specifications from official conference domains.
  • [COMMAND_EXECUTION]: The orchestration script (scripts/run_gates.py) and PDF verification module (scripts/_posterly/verify_final.py) utilize the subprocess module to execute internal Python scripts and system utilities like pdfinfo. The implementation uses list-based command construction with resolved absolute paths to mitigate potential shell injection vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:17 PM
Security Audit — agent-trust-hub — paper-poster-html