reader-panel
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-provided fiction chapters and story metadata to generate persona-based feedback. This content is inherently untrusted and could contain instructions intended to override the agent's behavior or the specific persona constraints.
- Ingestion points: The agent reads
story.md, individual chapter files, and the output generated by thestory contextcommand. - Boundary markers: The workflow utilizes subagents to isolate personas from each other and uses the
story contextcommand to limit the background information provided to the persona, which provides some structural isolation. - Capability inventory: The skill can execute shell commands via the
storyCLI, write feedback files to the local filesystem, and spawn subagents. - Sanitization: There is no evidence of explicit sanitization or filtering of the prose content to detect or neutralize embedded instructions before it is processed by the AI personas.
- [COMMAND_EXECUTION]: The skill workflow relies on the execution of several shell commands through a local CLI tool (
story). These commands include parameters derived from the user's project state, such as chapter ranges and round numbers. - Evidence: The skill calls
story build . --format html --stamp panel-round-{N},story context chapter-{NN} --path .,story reindex .,story links ., andstory validate .. While these are domain-specific project management commands, they represent a standard surface for command execution within the agent's environment.
Audit Metadata