scene-craft

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform project maintenance using the story CLI tool or a fallback Node.js script.
  • Executed commands include story reindex ., story links ., story validate ., story continuity ., and story pacing ..
  • The fallback mechanism uses bun run story -- or node ../story-maintenance/scripts/story.js, referencing a script in a neighboring directory within the repository structure.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves reading and updating external story project files (scenes, characters, plot, and continuity logs).
  • Ingestion points: Reads content from scenes/, characters/, plot/, and continuity/ directories.
  • Boundary markers: The workflow emphasizes structured data using YAML frontmatter and specific markdown headers (e.g., ## Planning, ## Scene Card, ## Sequel) to separate instructions from narrative content.
  • Capability inventory: The skill has the ability to write to the local filesystem and execute the story CLI validation tools.
  • Sanitization: The skill relies on specific machine-readable state fields (e.g., outcome, sequel, flashback-to) and the story validate command to ensure project consistency.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:19 AM
Security Audit — agent-trust-hub — scene-craft