feedback-triage

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses various command-line tools to manage the feedback workflow:
  • git tag for versioning feedback rounds.
  • gh issue list to retrieve reader notes from GitHub issues.
  • A custom story CLI for building HTML copies, comparing anchors, and maintaining story metadata (reindex, validate, continuity).
  • A fallback mechanism to execute a local script at a relative path using node ../story-maintenance/scripts/story.js or bun run story.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external resources and tools:
  • Interaction with GitHub's API via the gh CLI to fetch external reader feedback.
  • Dependencies on a 'Story Skills repository' for the story CLI tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a defined surface for indirect prompt injection as it ingests and processes untrusted text from external readers.
  • Ingestion points: External reader feedback is collected from GitHub issues and local markdown files (feedback/round-{N}/{reader-kebab}.md).
  • Boundary markers: Feedback is structured within markdown templates and YAML frontmatter, though no explicit "ignore instructions" delimiters are used for the reader content itself.
  • Capability inventory: The agent can perform file system writes (creating folders, stub files, and copying GitHub templates), execute shell commands, and trigger other skills based on the synthesized feedback.
  • Sanitization: The workflow involves quoting/paraphrasing feedback, but lacks specific escaping or validation logic to filter out potential malicious instructions embedded in reader notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:19 PM
Security Audit — agent-trust-hub — feedback-triage