specstory-link-trail

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill functions by executing two local Python scripts, parse_webfetch.py and generate_report.py. These scripts are used to process history files and format the results into a markdown report. The usage involves piping the output of the parser into the report generator.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from SpecStory history files (.specstory/history/*.md). These files contain conversation history, user messages, and tool outputs which are considered untrusted external data. If these histories contain adversarial instructions, they could potentially influence the agent when the final report is displayed.
  • Ingestion points: SpecStory history markdown files stored in the .specstory/history/ directory.
  • Boundary markers: The instructions in SKILL.md direct the agent to present the script output directly to the user. However, there are no explicit boundary markers or instructions to ignore embedded commands within the history content being summarized.
  • Capability inventory: The skill uses local file read access and Python script execution. It does not have network access or elevated privileges.
  • Sanitization: The generate_report.py script includes URL truncation to prevent overly long strings, and the references/url-categorization.md documentation suggests privacy-focused cleaning (such as removing tokens from URLs), although the primary parsing logic focuses on extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — specstory-link-trail