lookbook-dev

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is a comprehensive developer manual for the 'lookbook' package. It defines architecture layers and extension points for scorers, filters, and selectors without introducing any malicious instructions or bypasses.
  • [PROMPT_INJECTION]: The skill presents a potential surface for indirect prompt injection because it instructs the agent to ingest data from local project files (e.g., misc/docs/lookbook_development_plan.md) and image metadata. This is an inherent part of a developer-focused skill and does not represent an active threat.
  • Ingestion points: Documentation files in the misc/docs/ directory and image metadata provided through the ImageRef protocol.
  • Boundary markers: None specified in the instructions for delimiting untrusted content.
  • Capability inventory: The skill describes capabilities for file mapping via dol, registry-based class instantiation, and network service exposure via a built-in HTTP server.
  • Sanitization: No specific sanitization or validation logic for external content is described.
  • [COMMAND_EXECUTION]: Technical references to CLI tools (e.g., lookbook serve, lookbook mcp) are provided for standard development and operational tasks within the package ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 11:26 PM
Security Audit — agent-trust-hub — lookbook-dev