ljg-xray-book
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
Bashto execute theopencommand on a filename derived from user input ({书名}). This creates an attack surface where a book title containing shell metacharacters could result in command injection. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill ingests untrusted data from user-provided book titles, content, or external web links (Step 1).
- Boundary markers: Absent; there are no instructions to use delimiters or specific ignore-instructions for the external content.
- Capability inventory: The skill has the ability to write files via the
Writetool and execute shell commands viaBash(Step 4 and 5). - Sanitization: Absent; while the skill specifies some formatting (lowercase, spaces to hyphens), it does not require escaping or validation to prevent shell injection or prompt override from the ingested text.
Audit Metadata