publishing
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to execute various shell commands, including the project-specific 'story' CLI, standard utilities like 'grep' and 'java', and third-party formatting tools such as 'pagedjs-cli', 'weasyprint', and 'prince'. These tools are used for project validation, file indexing, and rendering manuscripts into PDF or EPUB formats.
- [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface for indirect prompt injection as it ingests untrusted data from the user's manuscript files.
- Ingestion points: The agent reads and processes files including 'story.md', 'matter/.md', and 'research/.md' to extract metadata, check permissions, and build the final book output.
- Boundary markers: The instructions do not define specific delimiters or warnings to prevent the agent from mistakenly interpreting instructions that may be embedded within the text of the book or research notes.
- Capability inventory: The skill possesses capabilities to read and write project files and execute shell commands via the 'story' CLI and other installed tools.
- Sanitization: There is no mention of sanitizing or escaping the manuscript content before it is interpolated into metadata builds or passed to rendering engines.
Audit Metadata