specstory-yak

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The utility script scripts/lib/utils.py executes the system git command using subprocess.run to retrieve author information via git blame. While the command uses a structured list of arguments and a timeout, it grants the skill the ability to invoke local system binaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes historical session data stored in .specstory/history/*.md. This data includes past user and agent messages which are treated as untrusted input. If a historical session contains malicious instructions, they could be ingested by the agent during analysis.
  • Ingestion points: Reads markdown files from the .specstory/history/ directory in scripts/lib/scoring.py via the analyze_session function.
  • Boundary markers: The parsing logic in scripts/lib/parser.py lacks explicit delimiters or instructions to ignore embedded prompts within the history files.
  • Capability inventory: The skill can execute the git command locally and write report files to user-specified paths on the filesystem.
  • Sanitization: No content sanitization or filtering is performed on the historical message text before it is summarized or analyzed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — specstory-yak