csv-to-latex-book

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/build_book.py invokes pdflatex using subprocess.run(). This is the core functionality of the skill. The implementation uses a list of arguments rather than a single shell string, which is a security best practice that prevents shell command injection.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates LaTeX source code (.tex files) based on user-provided CSV content and then compiles it. While dynamic code generation is often a risk, this script includes a comprehensive character sanitization map (ESC and UNI dictionaries in scripts/build_book.py) that escapes LaTeX control characters such as backslashes, braces, and percent signs, effectively neutralizing document-level injection attempts.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes external CSV data.
  • Ingestion points: The parse_csv function in scripts/build_book.py reads the entire contents of a user-provided CSV file.
  • Boundary markers: None explicitly present in the data processing layer, though the data is handled by a standalone Python script rather than the LLM directly.
  • Capability inventory: The skill can perform file writes (to create .tex and .pdf files) and execute the pdflatex binary.
  • Sanitization: The tex() function provides rigorous escaping of LaTeX special characters, significantly reducing the risk of malicious payloads in the CSV influencing the document compilation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 07:50 AM
Security Audit — agent-trust-hub — csv-to-latex-book