book-to-skill

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from files and URLs to generate instructions. While this is the intended purpose, it presents an inherent attack surface for indirect prompt injection if source documents contain malicious instructions.
  • Ingestion points: SKILL.md (Workflow Steps 1 & 2) describes validating input paths/URLs and extracting text from formats like PDF, HTML, and DOCX.
  • Boundary markers: None identified; the skill does not explicitly instruct the agent to ignore commands embedded within the processed document text.
  • Capability inventory: The agent is authorized to create and organize files (SKILL.md, SKILL_CARD.md, and references/) within the repository.
  • Sanitization: None identified; the workflow suggests paraphrasing but does not mandate specific sanitization or escaping of the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 03:33 PM
Security Audit — agent-trust-hub — book-to-skill