story-maintenance

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs mechanical maintenance by executing a bundled Node.js script 'scripts/story.js' and uses 'git show' to compare project versions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from user-authored markdown files (chapters, research notes, and plot summaries) to generate technical reports, pacing metrics, and structural diagrams. This creates a surface where instructions hidden in the story content could potentially affect the agent's behavior.
  • Ingestion points: Markdown files within the chapters/, research/, and matter/ directories, as well as project configuration in story.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when parsing content from these files.
  • Capability inventory: Execution of Node.js or Bun scripts and file system operations within the project directory.
  • Sanitization: The instructions do not describe any sanitization or validation of the content read from the markdown files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 01:19 PM
Security Audit — agent-trust-hub — story-maintenance