book-publisher
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local utility tools such as
bk-generate-book-metricsandbk-capture-screenshot, along with internal Python scripts likecollect-site-metrics.py, to aggregate project data and generate visual assets. It also generates and executes a Node.js script (generate.js) locally to programmatically create presentations. - [EXTERNAL_DOWNLOADS]: The
press-release-guide.mdutilizecurlto fetchsitemap.xmlfrom live URLs to verify project structure and content counts when local repository files are unavailable. - [DATA_EXFILTRATION]: The skill accesses project configuration files such as
mkdocs.ymlandbook-metrics.jsonto extract metrics and metadata. While the skill has network access capabilities viacurlfor sitemap retrieval, no evidence of unauthorized data transmission or exfiltration was found. - [PROMPT_INJECTION]: The guide for press releases instructs the agent to adopt a specific journalistic persona and tone ('AP style', 'neutral reported tone'), which are functional instructions for generating context-appropriate content.
Audit Metadata