story-init
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a shell command template for project initialization that is vulnerable to command injection. Specifically, the fallback execution path
node ../story-maintenance/scripts/story.js init "{Title}"uses double quotes to wrap the user-supplied{Title}variable. This allows shell metacharacters like backticks or$(...)to be interpreted and executed by the shell if an attacker provides a malicious story title. - [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection by ingesting multiple untrusted user inputs (Title, Genre, Synopsis, Era, POV, Tense, Themes) and interpolating them directly into shell commands and persistent project files.
- Ingestion points: User input gathered in Step 1 of the workflow (SKILL.md).
- Boundary markers: The skill relies on prose instructions to the agent rather than programmatic sanitization or structured data handling.
- Capability inventory: The skill utilizes shell command execution and file writing to the local filesystem.
- Sanitization: The instructions contain a warning to use single-quote escaping, but this is undermined by the inclusion of a vulnerable double-quoted example in the fallback path.
Audit Metadata