version-control

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown instructions and documentation. No Python, Node.js, or shell scripts are included, which eliminates the risk of direct malicious code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ingesting and merging untrusted narrative data from snapshot and branch files.
  • Ingestion points: Files located at versions/SNAPSHOT.md and versions/BRANCH.md, as well as CHANGE_IMPACT.md.
  • Boundary markers: None explicitly defined in the instructions to separate story content from agent instructions.
  • Capability inventory: The instructions call for file reads/writes and the use of coordination tools such as canon-manager and memory-manager.
  • Sanitization: None specified; the skill relies on mandatory manual author approval and explicit conflict resolution as safeguards.
  • [SAFE]: The workflow incorporates security best practices for automated agents, including branch isolation to prevent silent modification of the primary canon and mandatory review steps for high-risk changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 02:39 PM