AgentPod is building a private, secure device for your AI agent.The AgentPod device is coming.Coming soonBe first
We checked this and rejected itprivacy

book-to-skill: why it is not safe to use

We flagged this skill because it can publish generated book-derived content to GitHub, though only after explicit user opt-in and visibility confirmation.

What we found

Our review did not find hidden instructions, hardcoded secrets, obfuscated code, privilege escalation, or undisclosed remote code fetching. The main point that led to a warning is that this skill can publish generated, book-derived content to the user's GitHub account.

In the version we reviewed, that outbound publishing behavior is disclosed and gated. It requires the user to opt in, uses the GitHub account the user chose to connect, and includes a separate confirmation for private versus public visibility. We also found that its cleanup command is limited to the run-specific working directory described by the skill.

What to do instead

Use this skill only if you intend to send the generated output to GitHub and are comfortable choosing the target account and repository visibility at publish time. Before confirming publication, review the content for excerpts, notes, or other material you would not want stored in a repository.

If you want to keep all processing local and avoid any outbound publishing step, choose a workflow that saves results only to your local workspace and does not connect to GitHub.

Want the same outcome, safely? Use our checked skill instead.

Source: https://github.com/virgiliojr94/book-to-skill

We report what our security review found at the time we checked, with the goal of keeping people safe. Projects change; if a maintainer has since fixed this, we are glad to recheck it. Email hello@agentpod.com.

Copied to clipboard. Paste it into your AI (ChatGPT, Claude, or your agent) to add the skill.