theme-craft

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use a local CLI tool (story) for project maintenance tasks such as reindexing, link checking, and validation.
  • [DYNAMIC_EXECUTION]: The instructions include a fallback mechanism to execute a script using node or bun from a relative path (../story-maintenance/scripts/story.js), which constitutes dynamic execution of local scripts.
  • [INDIRECT_PROMPT_INJECTION]: 1. Ingestion points: The skill reads story.md and character files which contain user-authored narrative content and metadata. 2. Boundary markers: No specific delimiters are defined to separate user prose from the agent's instructions. 3. Capability inventory: The agent has the ability to write to project files and execute local shell commands. 4. Sanitization: The skill does not describe any validation or sanitization of the story content before processing it for thematic audits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:00 PM
Security Audit — agent-trust-hub — theme-craft