specstory-yak
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The utility script
scripts/lib/utils.pyexecutes the systemgitcommand usingsubprocess.runto retrieve author information viagit blame. While the command uses a structured list of arguments and a timeout, it grants the skill the ability to invoke local system binaries. - [INDIRECT_PROMPT_INJECTION]: The skill processes historical session data stored in
.specstory/history/*.md. This data includes past user and agent messages which are treated as untrusted input. If a historical session contains malicious instructions, they could be ingested by the agent during analysis. - Ingestion points: Reads markdown files from the
.specstory/history/directory inscripts/lib/scoring.pyvia theanalyze_sessionfunction. - Boundary markers: The parsing logic in
scripts/lib/parser.pylacks explicit delimiters or instructions to ignore embedded prompts within the history files. - Capability inventory: The skill can execute the
gitcommand locally and write report files to user-specified paths on the filesystem. - Sanitization: No content sanitization or filtering is performed on the historical message text before it is summarized or analyzed.
Audit Metadata