chapter-writing
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
storycommand-line utility for project maintenance, context gathering, and word count tracking. It also employslsto check for optional local directories and provides fallback execution paths usingnodeorbunfor its maintenance scripts.\n- [EXTERNAL_DOWNLOADS]: The skill mentions an external resource (github.com/forjd/better-writing) as an optional prose-improvement tool. It includes a specific instruction to the agent to obtain explicit user approval before performing any installation.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local project files, such as character profiles and plot outlines, to generate story content.\n - Ingestion points:
story.md, character files incharacters/, plot files inplot/, scene records, and continuity state files.\n - Boundary markers: None explicitly specified for the gathered context.\n
- Capability inventory: Execution of the
storyCLI and local script interpreters (node,bun).\n - Sanitization: Not present; the skill relies on the structured nature of the project files (Markdown and YAML).
Audit Metadata