feedback-triage
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses various command-line tools to manage the feedback workflow:
git tagfor versioning feedback rounds.gh issue listto retrieve reader notes from GitHub issues.- A custom
storyCLI for building HTML copies, comparing anchors, and maintaining story metadata (reindex, validate, continuity). - A fallback mechanism to execute a local script at a relative path using
node ../story-maintenance/scripts/story.jsorbun run story. - [EXTERNAL_DOWNLOADS]: The skill relies on external resources and tools:
- Interaction with GitHub's API via the
ghCLI to fetch external reader feedback. - Dependencies on a 'Story Skills repository' for the
storyCLI tool. - [INDIRECT_PROMPT_INJECTION]: The skill has a defined surface for indirect prompt injection as it ingests and processes untrusted text from external readers.
- Ingestion points: External reader feedback is collected from GitHub issues and local markdown files (
feedback/round-{N}/{reader-kebab}.md). - Boundary markers: Feedback is structured within markdown templates and YAML frontmatter, though no explicit "ignore instructions" delimiters are used for the reader content itself.
- Capability inventory: The agent can perform file system writes (creating folders, stub files, and copying GitHub templates), execute shell commands, and trigger other skills based on the synthesized feedback.
- Sanitization: The workflow involves quoting/paraphrasing feedback, but lacks specific escaping or validation logic to filter out potential malicious instructions embedded in reader notes.
Audit Metadata