book-study
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface through its knowledge ingestion process.
- Ingestion points: As described in
SKILL.mdunder Phase 2 (Read + Compile), the skill accepts untrusted external data including user notes, highlights, raw text, and file paths pointing to PDFs, TXT, or MD files. - Boundary markers: Absent. There are no specific isolation delimiters or operational instructions telling the agent to ignore prompt-like text patterns inside the book materials.
- Capability inventory: The skill is restricted to reading and writing markdown structures inside the localized
book-wiki/repository as outlined inSKILL.mdandreferences/page-templates.md. It does not request or utilize any shell command executions, subprocess spawning, or outbound network access. - Sanitization: Absent. The system parses and extracts text chunks directly into markdown files without validation or sanitization routines.
Audit Metadata