series-continuity

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a local CLI tool named story for project management tasks.
  • Evidence: The instructions include commands for project initialization (story init), link verification (story links), and series consistency checks (story series).
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by processing user-provided synopses and reading existing story project files.
  • Ingestion points: The skill ingests user input for {synopsis} and {Title}, and reads multiple local files including story.md, characters/_index.md, and continuity/state.md.
  • Boundary markers: No delimiters or instructions to ignore potential commands within the ingested content are present in the skill.
  • Capability inventory: The agent has the capability to write to the file system and execute local CLI commands based on the ingested data.
  • Sanitization: No explicit sanitization or validation of the input data is described before it is used in CLI arguments or file operations.
  • [DYNAMIC_EXECUTION]: The maintenance section provides a fallback execution path for a local script.
  • Evidence: The skill mentions running node ../story-maintenance/scripts/story.js when the primary CLI is unavailable, which involves executing a script from a relative directory path.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:19 PM
Security Audit — agent-trust-hub — series-continuity