plot-structure

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a CLI tool named story and provides a fallback to run a local JavaScript file using node from a relative path ../story-maintenance/scripts/story.js. This allows the agent to interact with the filesystem and perform project maintenance tasks.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided strings for arc names, chapter titles, and IDs, which are interpolated into shell command arguments (e.g., story add arc "{Name}"). This establishes an attack surface where malicious input could attempt command injection if the underlying execution environment does not provide sanitization, as the skill instructions do not explicitly include validation or escaping steps.
  • Ingestion points: User-supplied variables for story elements (names, titles, themes, and IDs) defined in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the interpolation prompts.
  • Capability inventory: The skill utilizes subprocess execution through the story CLI, bun, and node to manage files and metadata.
  • Sanitization: The instructions do not specify any validation, filtering, or escaping for the user-controlled variables before they are passed to the shell.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 03:22 AM
Security Audit — agent-trust-hub — plot-structure