skills/ethan-rio/skills/book-2-site/Gen Agent Trust Hub

book-2-site

Warn

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill implements a dynamic dependency management system in scripts/_venv.py and reference.md.
  • It automatically installs Python packages (pypdf, pymupdf) via pip into a virtual environment created in the user's current working directory.
  • For non-PDF formats, reference.md §6 instructs the agent to 'Research the best current Python library via WebSearch' and perform a pip install. This pattern delegates the selection of executable code to real-time LLM research, which can be manipulated by malicious search results or hallucination, leading to the installation of malicious packages.
  • [COMMAND_EXECUTION]: The skill uses high-privilege system calls to manage its execution environment.
  • In scripts/_venv.py, subprocess.check_call is used to invoke the pip module for package installation.
  • The script uses os.execv to replace the current process image with a new one using the virtual environment's interpreter. While common for bootstrapping, this allows the skill to bypass initial execution constraints by pivoting to a different runtime.
  • [PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection (Category 8).
  • Ingestion points: The agent reads the entire content of untrusted book files (PDF, EPUB, MD) chunk-by-chunk using the Read tool (Phase 2).
  • Boundary markers: The instructions lack explicit boundary markers or 'ignore embedded instructions' directives when processing book chunks.
  • Capability inventory: The agent has Bash, Write, and Edit capabilities. It is instructed to generate complex JavaScript objects and HTML files based on the book's content.
  • Sanitization: There is no sanitization of the book content before it is processed or used to generate the site's data. A malicious book could contain hidden instructions that cause the agent to exfiltrate data or write malicious code into the generated data.js or index.html files.
  • [DATA_EXFILTRATION]: While not directly exfiltrating data in the provided scripts, the skill's workflow involves reading local files and potentially performing network operations (WebSearch, WebFetch) based on instructions found in those files or during the 'research' phase, creating a potential exfiltration path.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 11:35 AM
Security Audit — agent-trust-hub — book-2-site