discover-books
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it retrieves book titles and descriptions from the external OpenLibrary API and processes them. Maliciously crafted data in the API response could attempt to influence the agent's behavior when displayed or stored in memory.\n
- Ingestion points: Data fetched from the OpenLibrary API in
src/openlibrary_client.py.\n - Boundary markers: No specific delimiters or boundary markers are used when presenting external metadata to the agent.\n
- Capability inventory: The skill can write discoveries to the agent's memory using
store_discoveriesinsrc/cli.py.\n - Sanitization: Descriptions are truncated to 500 characters and subjects are limited to 20 in
src/openlibrary_client.py, which provides a basic constraint on payload size.\n- [EXTERNAL_DOWNLOADS]: The skill fetches bibliographic data fromopenlibrary.org, a well-known and trusted public service. It also references theuvinstaller fromastral.sh.\n- [REMOTE_CODE_EXECUTION]: Therun.shscript includes a command to install theuvpackage manager viacurl | sh. This is a remote code execution pattern, although it targets a well-known and reputable developer tool.\n- [COMMAND_EXECUTION]: The skill usesuv runto execute local Python scripts and sanity checks to facilitate book discovery functionality.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata