qalam-assist-write-ebook

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from NotebookLM evidence notebooks, creating a surface for indirect prompt injection where malicious content in source documents could attempt to influence agent behavior.
  • Ingestion points: Data enters the context via notebooklm ask and notebooklm source list commands (SKILL.md, Step 7).
  • Boundary markers: Technical boundary markers (e.g., delimiters) are not explicitly implemented in the shell ingestion commands; however, the instruction set mandates manual review of every unit.
  • Capability inventory: The skill can execute CLI commands (notebooklm, npx) and write manuscript files to the local file system.
  • Sanitization: The workflow incorporates mandatory Author approval gates and a multi-pass revision process (references/prompt-library.md) designed to audit evidence and remove AI-generated errors.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download a supporting LaTeX component from a GitHub repository (https://github.com/ndpvt-web/latex-document-skill).
  • [COMMAND_EXECUTION]: The skill uses the notebooklm CLI for data retrieval and authentication, and the npx utility for skill management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 12:13 PM
Security Audit — agent-trust-hub — qalam-assist-write-ebook