deep-doc-reader

Pass

Audited by Gen Agent Trust Hub on Mar 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing untrusted document content.
  • Ingestion points: Content is ingested from user-provided PDF files or URLs and processed via the PageIndex MCP tool.
  • Boundary markers: The instructions do not define delimiters or specific 'ignore instructions' warnings for the agent to apply when reading extracted text.
  • Capability inventory: The skill utilizes the PageIndex MCP tool to construct hierarchical indexes and perform retrieval operations across external document data.
  • Sanitization: No sanitization or validation logic is specified for the text content retrieved from the external documents prior to its analysis by the AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 6, 2026, 04:19 PM