paper-talk
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The orchestration pipeline ingests untrusted text directly from user-provided documents within the paper directory to generate slides, speaker notes, and full speech scripts. If an untrusted or adversarial paper contains hidden instructions, it could manipulate the behavior of the agent or the underlying Codex models during the extraction or polish phases.
- Ingestion points: Source files located in
PAPER_DIR/main.texandPAPER_DIR/sections/*.texas defined in the Inputs section. - Boundary markers: Absent; there are no clear delimiters or structural isolations specified in the prompt orchestration to prevent content from being interpreted as instructions.
- Capability inventory: The skill allows comprehensive command execution via
Bash(*),Write, andEdittools to handle document management and file creation. - Sanitization: The skill relies on post-generation audits (such as claim and citation checks) rather than preprocessing sanitization or validation of the input text.
- [COMMAND_EXECUTION]: The workflow runs local command-line tools such as
latexmk,soffice(LibreOffice headless mode),pdfinfo, andpdftoppmusing theBash(*)tool to recompile Beamer slides and perform export integrity checks. Although these commands are standard for academic slide production, invoking them programmatically creates a dependency on local system binaries.
Audit Metadata