story-maintenance
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs mechanical maintenance by executing a bundled Node.js script 'scripts/story.js' and uses 'git show' to compare project versions.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from user-authored markdown files (chapters, research notes, and plot summaries) to generate technical reports, pacing metrics, and structural diagrams. This creates a surface where instructions hidden in the story content could potentially affect the agent's behavior.
- Ingestion points: Markdown files within the chapters/, research/, and matter/ directories, as well as project configuration in story.md.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when parsing content from these files.
- Capability inventory: Execution of Node.js or Bun scripts and file system operations within the project directory.
- Sanitization: The instructions do not describe any sanitization or validation of the content read from the markdown files before processing.
Audit Metadata