revision-continuity

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes a large volume of untrusted data from user-provided project files to perform complex revision tasks, creating an attack surface for instructions embedded within story content. 1. Ingestion points: Reads from story.md, all files in chapters/, plot/, scenes/, continuity/, and research/ directories. 2. Boundary markers: The instructions lack specific guidance on using delimiters or ignoring embedded instructions in the processed data. 3. Capability inventory: Executes story CLI, git commands, and local scripts; performs extensive file system writes and renames. 4. Sanitization: No explicit sanitization or validation of the markdown content is required before processing.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution for its core functionality, including project maintenance and snapshots.
  • Invokes the story CLI for tasks like continuity, pacing, voices, and wordcount.
  • Uses git for project snapshots, including git init, git add, git commit, and git tag.
  • Includes a fallback to execute a local utility script via node or bun located at ../story-maintenance/scripts/story.js relative to the skill directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 09:20 AM
Security Audit — agent-trust-hub — revision-continuity