audiobook-production

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has an inherent surface for indirect prompt injection because its core functionality involves processing user-supplied content such as manuscripts and audio configuration data.
  • Ingestion points: In SKILL.md, the 'How to Use' and 'Step 2: Prepare the Manuscript' sections describe the agent ingesting user-provided manuscripts, chapter lists, and audio technical specifications.
  • Boundary markers: The instructions do not define specific delimiters or boundary markers to isolate the user-provided data from the system's instructions.
  • Capability inventory: Across the skill documentation, capabilities are limited to text-based planning, scheduling, and template generation. No scripts or instructions for network operations, file-system writes, or code execution are present.
  • Sanitization: The skill does not include specific sanitization or validation steps for the manuscript content prior to processing.
  • [SAFE]: The skill refers to well-known and trusted entities such as ACX (Audible), iZotope, and academic sources (Richard Mayer). All external references and configuration fields, including the referenced MCP server '@clawfu/mcp-skills', are consistent with the author's identity and the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:25 PM
Security Audit — agent-trust-hub — audiobook-production