llmwhisperer

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references the official llmwhisperer-client library for Python and JavaScript (npm), as well as the n8n-nodes-unstract package for workflow integration.
  • [COMMAND_EXECUTION]: Provides a Docker command example for running an MCP server (unstract/mcp-server), which is a legitimate configuration step for developers using the Unstract platform.
  • [DATA_EXFILTRATION]: The skill facilitates the transmission of document data (PDFs, images, Office files) to external processing endpoints at llmwhisperer-api.us-central.unstract.com and llmwhisperer-api.eu-west.unstract.com. This data transfer is the intended functional purpose of the OCR service and is performed via authenticated API requests.
  • [PROMPT_INJECTION]: The skill processes external document content, which presents a surface for indirect prompt injection.
  • Ingestion points: Document uploads and URL-based extraction specified in SKILL.md and references/api_reference.md.
  • Boundary markers: None described in the provided documentation.
  • Capability inventory: Includes network operations to Unstract APIs and file reading via client libraries.
  • Sanitization: Not explicitly mentioned in the documentation for extracted text.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 12:37 PM
Security Audit — agent-trust-hub — llmwhisperer