book-publisher

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local utility tools such as bk-generate-book-metrics and bk-capture-screenshot, along with internal Python scripts like collect-site-metrics.py, to aggregate project data and generate visual assets. It also generates and executes a Node.js script (generate.js) locally to programmatically create presentations.
  • [EXTERNAL_DOWNLOADS]: The press-release-guide.md utilize curl to fetch sitemap.xml from live URLs to verify project structure and content counts when local repository files are unavailable.
  • [DATA_EXFILTRATION]: The skill accesses project configuration files such as mkdocs.yml and book-metrics.json to extract metrics and metadata. While the skill has network access capabilities via curl for sitemap retrieval, no evidence of unauthorized data transmission or exfiltration was found.
  • [PROMPT_INJECTION]: The guide for press releases instructs the agent to adopt a specific journalistic persona and tone ('AP style', 'neutral reported tone'), which are functional instructions for generating context-appropriate content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 01:28 PM
Security Audit — agent-trust-hub — book-publisher