character-management
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to command injection through the interpolation of user-supplied data into shell commands. This could allow a malicious user to execute arbitrary commands by providing a character name containing shell metacharacters.
- Ingestion points: User-provided character names, roles, and old names (for renaming) are used as arguments in
SKILL.mdfor CLI commands. - Boundary markers: The instructions use double quotes (e.g.,
story names "{Name}") which are insufficient to prevent shell injection in many environments. - Capability inventory: The skill utilizes shell-based tools including a custom
storyCLI,bun,node, andgrep(e.g.,grep -rn "Old Name" .). - Sanitization: No sanitization or validation logic is specified to check user input for shell metacharacters before execution.
- [COMMAND_EXECUTION]: The skill relies on executing external commands (
story,bun,node,grep) to perform core functions like indexing, linking, and validating story data. While these are intended for project maintenance, their use with unsanitized input poses a risk.
Audit Metadata