discovery-drafting
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to perform project maintenance using the story CLI tool or a local fallback script located at
../story-maintenance/scripts/story.js. These tasks include word counting, link validation, and re-indexing of project files. - [INDIRECT_PROMPT_INJECTION]: The core reconciliation loop requires the agent to read and analyze user-written chapter prose to extract new characters, locations, and narrative promises. This ingestion of untrusted content into the agent's context establishes an indirect prompt injection surface.
- Ingestion points: Chapter markdown files, specifically sections under
## Chapter Text. - Boundary markers: The instructions do not define specific delimiters to separate user-provided narrative text from the agent's instructions, though it distinguishes between notes and prose for word-count purposes.
- Capability inventory: The agent can execute shell commands via the story tool and write to the local filesystem.
- Sanitization: The skill mandates a human-in-the-loop step, where all entity candidates extracted from the prose must be presented for user approval before any bible files are created or modified.
Audit Metadata