Security audit
KDP Publisher DE
Security checks for vulnerabilities and agentic risk
Overview
The skill mostly matches its PDF-building purpose, but one compiler path can automatically read and upload extra local files referenced by Typst includes to an external service without clear path limits.
Review this skill before installing if you handle private manuscripts. It appears to be a legitimate PDF builder, but avoid compiling untrusted Typst files, check which files are included before remote compilation, and consider using a local Typst compiler or a locked-down project directory for sensitive work.
Static analysis
No suspicious patterns detected.
