ingest-kindle

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the subprocess.run method in formats.py to invoke the ebook-convert command-line utility (part of the Calibre suite). This is used to handle conversion for .mobi and .azw3 formats. The implementation uses list-based arguments without a shell, which follows security best practices for executing external commands.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes and extracts text from external ebook files and highlight logs.
  • Ingestion points: Untrusted data is ingested from user-provided Kindle ebook files (.epub, .mobi, .azw3) and the My Clippings.txt file via clippings.py and formats.py.
  • Boundary markers: The skill appends an <!-- EXTRACTION_COMPLETE --> marker to the extracted text to signal completion to downstream tools, but it does not include explicit delimiters or instructions to ignore potential commands embedded within the book text.
  • Capability inventory: The skill has the capability to execute subprocesses (ebook-convert) and write extracted text and metadata to the local filesystem in the ~/clawd/library/books/ directory.
  • Sanitization: The skill performs basic HTML tag stripping and sanitizes filenames using a slugification function, but it does not filter or sanitize the extracted natural language content for malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — ingest-kindle