paper-talk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The orchestration pipeline ingests untrusted text directly from user-provided documents within the paper directory to generate slides, speaker notes, and full speech scripts. If an untrusted or adversarial paper contains hidden instructions, it could manipulate the behavior of the agent or the underlying Codex models during the extraction or polish phases.
  • Ingestion points: Source files located in PAPER_DIR/main.tex and PAPER_DIR/sections/*.tex as defined in the Inputs section.
  • Boundary markers: Absent; there are no clear delimiters or structural isolations specified in the prompt orchestration to prevent content from being interpreted as instructions.
  • Capability inventory: The skill allows comprehensive command execution via Bash(*), Write, and Edit tools to handle document management and file creation.
  • Sanitization: The skill relies on post-generation audits (such as claim and citation checks) rather than preprocessing sanitization or validation of the input text.
  • [COMMAND_EXECUTION]: The workflow runs local command-line tools such as latexmk, soffice (LibreOffice headless mode), pdfinfo, and pdftoppm using the Bash(*) tool to recompile Beamer slides and perform export integrity checks. Although these commands are standard for academic slide production, invoking them programmatically creates a dependency on local system binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — paper-talk