csv-to-latex-book
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/build_book.pyinvokespdflatexusingsubprocess.run(). This is the core functionality of the skill. The implementation uses a list of arguments rather than a single shell string, which is a security best practice that prevents shell command injection. - [DYNAMIC_EXECUTION]: The skill dynamically generates LaTeX source code (
.texfiles) based on user-provided CSV content and then compiles it. While dynamic code generation is often a risk, this script includes a comprehensive character sanitization map (ESCandUNIdictionaries inscripts/build_book.py) that escapes LaTeX control characters such as backslashes, braces, and percent signs, effectively neutralizing document-level injection attempts. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it processes external CSV data.
- Ingestion points: The
parse_csvfunction inscripts/build_book.pyreads the entire contents of a user-provided CSV file. - Boundary markers: None explicitly present in the data processing layer, though the data is handled by a standalone Python script rather than the LLM directly.
- Capability inventory: The skill can perform file writes (to create
.texand.pdffiles) and execute thepdflatexbinary. - Sanitization: The
tex()function provides rigorous escaping of LaTeX special characters, significantly reducing the risk of malicious payloads in the CSV influencing the document compilation process.
Audit Metadata