publishing

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute various shell commands, including the project-specific 'story' CLI, standard utilities like 'grep' and 'java', and third-party formatting tools such as 'pagedjs-cli', 'weasyprint', and 'prince'. These tools are used for project validation, file indexing, and rendering manuscripts into PDF or EPUB formats.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface for indirect prompt injection as it ingests untrusted data from the user's manuscript files.
  • Ingestion points: The agent reads and processes files including 'story.md', 'matter/.md', and 'research/.md' to extract metadata, check permissions, and build the final book output.
  • Boundary markers: The instructions do not define specific delimiters or warnings to prevent the agent from mistakenly interpreting instructions that may be embedded within the text of the book or research notes.
  • Capability inventory: The skill possesses capabilities to read and write project files and execute shell commands via the 'story' CLI and other installed tools.
  • Sanitization: There is no mention of sanitizing or escaping the manuscript content before it is interpolated into metadata builds or passed to rendering engines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 09:20 AM
Security Audit — agent-trust-hub — publishing