Back to skill

Security audit

KDP Publisher

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent KDP book-production helper, with expected but notable use of Google AI APIs, local output files, KDP upload guidance, and paid ads guidance.

Install in a virtual environment, pin dependencies where possible, prefer an environment variable or secret manager over passing API keys on the command line, and review every KDP submission, pricing choice, AI disclosure, and Amazon Ads campaign before allowing an agent to upload, submit, or launch anything that affects your Amazon account or ad spend.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:253
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/validate-book.py:571
Finding

Validator Loads API Credentials Unnecessarily and Supports Secrets in Process Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

While most of this is description mismatch, the undeclared use of local credentials and external AI-based processing is security-relevant. Mentioning API key loading from environment variables, CLI arguments, or local credential files without explicit disclosure of those data flows can cause unintended credential exposure or unauthorized external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding

While most of this is description mismatch, the undeclared use of local credentials and external AI-based processing is security-relevant. Mentioning API key loading from environment variables, CLI arguments, or local credential files without explicit disclosure of those data flows can cause unintended credential exposure or unauthorized external data transmission.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

While most of this is description mismatch, the undeclared use of local credentials and external AI-based processing is security-relevant. Mentioning API key loading from environment variables, CLI arguments, or local credential files without explicit disclosure of those data flows can cause unintended credential exposure or unauthorized external data transmission.

Content

No source excerpt is available for this finding.

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

document.querySelector('input[type=file]').dispatchEvent(new Event('change', {bubbles:true}));

text
- Wait for `#data-print-book-interior-processing-status` to show COMPLETED before proceeding
- Reload KDP page before each upload session — stale form state causes silent failures

**Category selection:**
- Use the cascade-select dropdowns in the category modal

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill references local scripts, environment variables, credential files, and file-producing workflows, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, this can lead to overbroad access assumptions and unsafe execution of file write or env-reading actions beyond what the user intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly broad triggers can cause the skill to activate for generic book-creation or publishing requests, leading an agent to load instructions involving script execution, credential usage, file generation, or browser automation when the user did not ask for that level of action. In agent systems, unintended invocation increases the chance of overreach and misuse of powerful capabilities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest and top-level description frame this skill as helping create, format, and publish children's and activity books to Amazon KDP, including story generation, PDF assembly, covers, metadata, and upload guidance. The dedicated 'Amazon Ads Quick-Start' section adds marketing/advertising campaign management capabilities that are not justified by that stated publishing-focused purpose.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
5. **No text in AI illustrations**: Every image prompt must include "no text, no words, no letters". Text baked into AI images is often garbled. Always overlay text programmatically.

6. **Descriptions from finished content**: Never write the description from the original prompt. Write it after the story is final — use actual character names and plot.

7. **KDP categories**: Select via cascade dropdowns in the modal, then JS-click the placement checkbox. Don't rely on Playwright click for the final checkbox.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script transmits user-provided prompts and derived scene descriptions to external Google AI services for text and image generation, but gives no explicit notice or consent flow before sending potentially sensitive content off-host. In an agent-skill context, prompts may contain proprietary, personal, or unpublished manuscript data, so silent exfiltration to a third party creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

When --check-text-in-images is used, the script transmits local image contents to Gemini Vision, but the messaging does not clearly and prominently warn that files are being sent to an external third-party service. In a publishing workflow, these images may be unpublished or sensitive commercial content, so undisclosed exfiltration to a remote API is a real privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/validate-book.py (reported line 358)May include surrounding context.

python
{
                                "inline_data": {
                                    "mime_type": "image/png",
                                    "data": __import__("base64").b64encode(img_data).decode(),
                                }
                            },
                            {

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/validate-book.py (reported line 459)May include surrounding context.

python
pages = convert_from_path(str(pdf_path), dpi=72, first_page=1, last_page=10)
        blank_pages = []
        for i, page_img in enumerate(pages):
            arr = __import__("numpy").array(page_img.convert("L"))
            if arr.std() < 3.0:  # Near-zero variance = blank white page
                blank_pages.append(i + 1)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The validator silently loads a Google AI API key from a user-specific credential file outside the declared command-line inputs. That expands the tool's access scope unexpectedly and can cause downstream network actions to occur with ambient credentials the user did not explicitly provide, violating least surprise and least privilege.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file gives step-by-step instructions to create and launch a paid advertising campaign, including a no-end-date setting and daily budget, but it does not explicitly warn users that this will incur real charges. Because the guidance could affect user finances, a user-facing warning about paid spend and monitoring costs is appropriate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This function accesses sensitive credentials from GOOGLE_AI_API_KEY or ~/.clawdbot/credentials/google_ai.json. There is no user-facing disclosure beyond operational setup text, so the skill lacks a clear warning that it will read secrets from the environment or filesystem.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Accessing a sensitive credential file in a hidden user directory without clear disclosure is a transparency and trust-boundary issue. Even if the key is only used for the validator's stated image-check feature, undeclared credential harvesting behavior is risky in an agent skill because users may not expect local secret material to be read automatically.

Content

No source excerpt is available for this finding.