ingest-kindle
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
subprocess.runmethod informats.pyto invoke theebook-convertcommand-line utility (part of the Calibre suite). This is used to handle conversion for .mobi and .azw3 formats. The implementation uses list-based arguments without a shell, which follows security best practices for executing external commands. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes and extracts text from external ebook files and highlight logs.
- Ingestion points: Untrusted data is ingested from user-provided Kindle ebook files (.epub, .mobi, .azw3) and the
My Clippings.txtfile viaclippings.pyandformats.py. - Boundary markers: The skill appends an
<!-- EXTRACTION_COMPLETE -->marker to the extracted text to signal completion to downstream tools, but it does not include explicit delimiters or instructions to ignore potential commands embedded within the book text. - Capability inventory: The skill has the capability to execute subprocesses (
ebook-convert) and write extracted text and metadata to the local filesystem in the~/clawd/library/books/directory. - Sanitization: The skill performs basic HTML tag stripping and sanitizes filenames using a slugification function, but it does not filter or sanitize the extracted natural language content for malicious instructions.
Audit Metadata