skills/xberg-io/xberg/kreuzberg/Gen Agent Trust Hub

kreuzberg

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation references installation from standard public registries including PyPI (kreuzberg), NPM (@kreuzberg/node), and Crates.io (kreuzberg-cli), as well as GitHub releases. These are standard distribution channels for the vendor's software.
  • [PROMPT_INJECTION]: The skill is a documentation-only resource and does not contain any instructions that attempt to override agent safety guidelines or system prompts.
  • [INDIRECT_PROMPT_INJECTION]: As a document extraction utility, the skill processes untrusted external files (PDFs, Office docs, etc.). This represents an attack surface where an agent might process malicious instructions embedded within extracted text if the content is not properly delimited or sanitized.
  • Ingestion points: Document file paths and raw bytes processed through extraction functions.
  • Boundary markers: The skill does not provide automatic prompt delimiters for the extracted content.
  • Capability inventory: File system read access (for documents) and CPU-bound parsing/OCR; no network exfiltration or shell execution is present in the core library documentation.
  • Sanitization: No content sanitization is described for the extracted output.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 07:33 PM
Security Audit — agent-trust-hub — kreuzberg