line-editing
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-generated story content, which could theoretically contain embedded instructions designed to hijack the agent's behavior.
- Ingestion points: The agent reads
story.md, chapter markdown files (specifically under## Chapter Text), character entity files, andstyle-sheet.mdto perform editing and voice analysis. - Boundary markers: The instructions mandate working paragraph-by-paragraph and following structured checklists provided in the
references/directory. - Capability inventory: The agent can execute shell commands via the
storyCLI for analysis and building narration/HTML copies, and can invoke system text-to-speech utilities. - Sanitization: The workflow requires the agent to propose every change with a before/after comparison and a rationale, ensuring the user reviews and accepts edits before they are applied to the markdown files.
- [COMMAND_EXECUTION]: The skill heavily utilizes a custom
storyCLI tool and system-level audio utilities to perform its functions. - Evidence: Throughout
SKILL.md, there are numerous calls tostory passes,story prose,story voices,story build, andstory wordcountfor manuscript management. - Evidence: The skill uses
command -vto detect and then utilize OS text-to-speech tools such assay(macOS),espeak-ng, orspd-say(Linux) to perform a read-aloud pass. - [EXTERNAL_DOWNLOADS]: The skill references external third-party software for rendering and accessibility features.
- Evidence: Mentions external paged-media engines like Paged.js CLI, WeasyPrint, and Prince for generating PDF/print versions of the story.
- Safety check: The instructions explicitly direct the agent to "ask before installing anything" when a required system tool or package is missing, maintaining user control over environment changes.
Audit Metadata