calibre-library
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.runto execute thepgreputility to check for active Calibre processes, ensuring the library database is not locked. It also uses standard Calibre command-line tools such ascalibredbandcalibre-debug, alongside system utilities likezip -dandgio trash, for ebook library maintenance and file management tasks.\n- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external and untrusted data by parsing EPUB metadata and internal structures, as well as referencing Wikipedia for title casing rules, which introduces a potential attack surface for indirect injection.\n - Ingestion points: The skill reads metadata from internal EPUB components (OPF files, containers) and local database entries.\n
- Boundary markers: A strict operational cycle is enforced where the agent must provide a diagnostic report and recommendations, requiring an explicit user "ok" before any changes are applied.\n
- Capability inventory: The skill is capable of performing write operations on the local library database and ebook files, including modifying archives and deleting files.\n
- Sanitization: Implements normalization for metadata and provides specific instructions for the agent to identify and remove sensitive buyer identifiers (PII) without ever outputting their values to the agent's display.
Audit Metadata