character-management

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to command injection through the interpolation of user-supplied data into shell commands. This could allow a malicious user to execute arbitrary commands by providing a character name containing shell metacharacters.
  • Ingestion points: User-provided character names, roles, and old names (for renaming) are used as arguments in SKILL.md for CLI commands.
  • Boundary markers: The instructions use double quotes (e.g., story names "{Name}") which are insufficient to prevent shell injection in many environments.
  • Capability inventory: The skill utilizes shell-based tools including a custom story CLI, bun, node, and grep (e.g., grep -rn "Old Name" .).
  • Sanitization: No sanitization or validation logic is specified to check user input for shell metacharacters before execution.
  • [COMMAND_EXECUTION]: The skill relies on executing external commands (story, bun, node, grep) to perform core functions like indexing, linking, and validating story data. While these are intended for project maintenance, their use with unsanitized input poses a risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 04:42 AM
Security Audit — agent-trust-hub — character-management