lookbook-dev
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a comprehensive developer manual for the 'lookbook' package. It defines architecture layers and extension points for scorers, filters, and selectors without introducing any malicious instructions or bypasses.
- [PROMPT_INJECTION]: The skill presents a potential surface for indirect prompt injection because it instructs the agent to ingest data from local project files (e.g.,
misc/docs/lookbook_development_plan.md) and image metadata. This is an inherent part of a developer-focused skill and does not represent an active threat. - Ingestion points: Documentation files in the
misc/docs/directory and image metadata provided through theImageRefprotocol. - Boundary markers: None specified in the instructions for delimiting untrusted content.
- Capability inventory: The skill describes capabilities for file mapping via
dol, registry-based class instantiation, and network service exposure via a built-in HTTP server. - Sanitization: No specific sanitization or validation logic for external content is described.
- [COMMAND_EXECUTION]: Technical references to CLI tools (e.g.,
lookbook serve,lookbook mcp) are provided for standard development and operational tasks within the package ecosystem.
Audit Metadata