ingest-book
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.Popento launch the Readarr binary andsubprocess.runto execute an external 'extractor' skill. These operations are used to manage local service state and facilitate cross-skill data processing. - [EXTERNAL_DOWNLOADS]: The skill interacts with external Newznab indexers (e.g., NZBGeek, DrunkenSlug, Althub) and local Readarr APIs to fetch book metadata. Network operations use HTTPS and are restricted to services required for book ingestion.
- [PROMPT_INJECTION]: The skill processes untrusted metadata from external sources (book titles, descriptions, authors) and stores it in the agent's memory. This creates a surface for indirect prompt injection (Category 8), though the risk is mitigated by the skill's specific focus on metadata extraction.
- [CREDENTIALS_UNSAFE]: The skill handles API keys for multiple services. It implements security best practices by loading keys from environment variables or local config files and explicitly masking these keys when displaying them in logs or tables.
- [DYNAMIC_EXECUTION]: Local Python modules are loaded dynamically via
importlib.utilto facilitate taxonomy integration. The module paths are programmatically constructed from the skill's own directory structure, reducing the risk of arbitrary code loading.
Audit Metadata