audiobook-production
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill has an inherent surface for indirect prompt injection because its core functionality involves processing user-supplied content such as manuscripts and audio configuration data.
- Ingestion points: In SKILL.md, the 'How to Use' and 'Step 2: Prepare the Manuscript' sections describe the agent ingesting user-provided manuscripts, chapter lists, and audio technical specifications.
- Boundary markers: The instructions do not define specific delimiters or boundary markers to isolate the user-provided data from the system's instructions.
- Capability inventory: Across the skill documentation, capabilities are limited to text-based planning, scheduling, and template generation. No scripts or instructions for network operations, file-system writes, or code execution are present.
- Sanitization: The skill does not include specific sanitization or validation steps for the manuscript content prior to processing.
- [SAFE]: The skill refers to well-known and trusted entities such as ACX (Audible), iZotope, and academic sources (Richard Mayer). All external references and configuration fields, including the referenced MCP server '@clawfu/mcp-skills', are consistent with the author's identity and the skill's stated purpose.
Audit Metadata