book-2-site
Warn
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill implements a dynamic dependency management system in
scripts/_venv.pyandreference.md. - It automatically installs Python packages (
pypdf,pymupdf) viapipinto a virtual environment created in the user's current working directory. - For non-PDF formats,
reference.md§6 instructs the agent to 'Research the best current Python library via WebSearch' and perform apip install. This pattern delegates the selection of executable code to real-time LLM research, which can be manipulated by malicious search results or hallucination, leading to the installation of malicious packages. - [COMMAND_EXECUTION]: The skill uses high-privilege system calls to manage its execution environment.
- In
scripts/_venv.py,subprocess.check_callis used to invoke thepipmodule for package installation. - The script uses
os.execvto replace the current process image with a new one using the virtual environment's interpreter. While common for bootstrapping, this allows the skill to bypass initial execution constraints by pivoting to a different runtime. - [PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection (Category 8).
- Ingestion points: The agent reads the entire content of untrusted book files (PDF, EPUB, MD) chunk-by-chunk using the
Readtool (Phase 2). - Boundary markers: The instructions lack explicit boundary markers or 'ignore embedded instructions' directives when processing book chunks.
- Capability inventory: The agent has
Bash,Write, andEditcapabilities. It is instructed to generate complex JavaScript objects and HTML files based on the book's content. - Sanitization: There is no sanitization of the book content before it is processed or used to generate the site's data. A malicious book could contain hidden instructions that cause the agent to exfiltrate data or write malicious code into the generated
data.jsorindex.htmlfiles. - [DATA_EXFILTRATION]: While not directly exfiltrating data in the provided scripts, the skill's workflow involves reading local files and potentially performing network operations (
WebSearch,WebFetch) based on instructions found in those files or during the 'research' phase, creating a potential exfiltration path.
Audit Metadata