write-stories

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs environment checks and setup including identifying the project's tech stack by reading dependency manifests (e.g., package.json, go.mod, requirements.txt) and ensuring project directory structures exist (mkdir). These are standard behaviors for its stated purpose.
  • [DATA_EXFILTRATION]: The skill reads project configuration and documentation files (roadmap items, research findings, and technical specs) to inform the story-writing process. This data access is limited to the local filesystem, and no network exfiltration patterns were detected.
  • [PROMPT_INJECTION]: The skill processes project-specific data which serves as a surface for indirect prompt injection. Malicious instructions embedded in roadmap or research files could theoretically influence agent behavior.
  • Ingestion points: Files located in docs/roadmap/, docs/specs/, docs/research/, and project dependency manifests.
  • Boundary markers: Not explicitly defined for the interpolation of ingested file content into agent prompts.
  • Capability inventory: The skill uses TeamCreate and Agent to orchestrate multiple models, uses SendMessage for inter-agent communication, and has broad file read/write access to project documentation.
  • Sanitization: No explicit validation, escaping, or filtering of content from external project files is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 02:02 PM