ingest-audiobook

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Shell scripts run.sh and run-faster.sh generate Python code at runtime using heredocs to interpolate local file paths into the script. This pattern is vulnerable to code injection if a file in the processing inbox has a maliciously crafted name designed to escape the string context.
  • [REMOTE_CODE_EXECUTION]: The skill dynamically downloads and executes external software packages including audible-cli, openai-whisper, and faster-whisper via uvx and pip during runtime.
  • [COMMAND_EXECUTION]: Extensive use of subprocess and direct shell calls to manage system utilities such as ffmpeg, ffprobe, nvidia-smi, pgrep, and xargs for decryption, media conversion, and pipeline monitoring.
  • [COMMAND_EXECUTION]: The memory_integration.py module uses importlib.util to dynamically load Python code from computed local file paths.
  • [EXTERNAL_DOWNLOADS]: Fetches external content including encrypted audiobooks from Audible (requiring user authentication) and model weights for the Whisper transcription engine. References to documentation for the well-known Coqui TTS service are also included.
  • [PROMPT_INJECTION]: The skill processes untrusted text data from audiobooks and YouTube lore transcripts (ingestion points in transcribe_runner.py and youtube_lore_downloader.py). This ingested data is used to populate memory and influence agent personality without explicit sanitization or boundary markers, creating a surface for indirect prompt injection that could leverage the agent's Bash tool capabilities.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ingest-audiobook