premise-workshop

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local system using a command-line interface tool named story. It executes commands such as story init to create new projects and story names to check for character or title name collisions. These commands are part of the vendor's own toolkit (danjdewhurst) and are used for functional project maintenance.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-generated story ideas, titles, and loglines, which are subsequently passed as arguments to shell commands. This creates a potential indirect prompt injection surface. However, the skill provides explicit, high-quality security instructions for the agent to sanitize this input: it requires wrapping all values in single quotes and correctly escaping internal single quotes (e.g., transforming it's to 'it' extquotesingle{}s'). This practice effectively mitigates the risk of command injection via subshell execution ($(...)) or backticks.
  • [EXTERNAL_DOWNLOADS]: The workflow includes a 'sanity-check' phase where the agent is instructed to verify the existence of comparable book titles provided by the user. This involves standard web search functionality to check metadata (titles/authors) and does not involve the execution of remote code or the downloading of untrusted assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:19 AM
Security Audit — agent-trust-hub — premise-workshop