specstory-organize

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute a local Python script, scripts/organize.py. This script is responsible for creating directories and moving history files within the user's project structure. The operations are limited to the .specstory/history path.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans filenames in the .specstory/history directory to determine organization structure, which constitutes a data ingestion surface.
  • Ingestion points: Filenames are retrieved from the local filesystem via os.listdir in scripts/organize.py.
  • Boundary markers: None present in the prompt instructions to delimit the untrusted filename data.
  • Capability inventory: The skill has the ability to write to the filesystem (creating directories) and move files. It does not possess network or shell execution capabilities that act directly on filename content.
  • Sanitization: The script implements strict regex validation (r'^(\d{4})-(\d{2})-\d{2}_') to ensure only files with valid date timestamps are processed, mitigating risks from malformed filenames.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — specstory-organize