premise-workshop
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the local system using a command-line interface tool named
story. It executes commands such asstory initto create new projects andstory namesto check for character or title name collisions. These commands are part of the vendor's own toolkit (danjdewhurst) and are used for functional project maintenance. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-generated story ideas, titles, and loglines, which are subsequently passed as arguments to shell commands. This creates a potential indirect prompt injection surface. However, the skill provides explicit, high-quality security instructions for the agent to sanitize this input: it requires wrapping all values in single quotes and correctly escaping internal single quotes (e.g., transforming
it'sto'it' extquotesingle{}s'). This practice effectively mitigates the risk of command injection via subshell execution ($(...)) or backticks. - [EXTERNAL_DOWNLOADS]: The workflow includes a 'sanity-check' phase where the agent is instructed to verify the existence of comparable book titles provided by the user. This involves standard web search functionality to check metadata (titles/authors) and does not involve the execution of remote code or the downloading of untrusted assets.
Audit Metadata