deep-doc-reader
Pass
Audited by Gen Agent Trust Hub on Mar 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing untrusted document content.
- Ingestion points: Content is ingested from user-provided PDF files or URLs and processed via the PageIndex MCP tool.
- Boundary markers: The instructions do not define delimiters or specific 'ignore instructions' warnings for the agent to apply when reading extracted text.
- Capability inventory: The skill utilizes the PageIndex MCP tool to construct hierarchical indexes and perform retrieval operations across external document data.
- Sanitization: No sanitization or validation logic is specified for the text content retrieved from the external documents prior to its analysis by the AI model.
Audit Metadata