verse-craft

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use a project-specific CLI tool (story) for managing story components, including adding matter files and performing project maintenance (e.g., story wordcount --write, story links, story validate). It also utilizes system text-to-speech utilities such as say (macOS), espeak-ng, or spd-say (Linux) to assist in checking the rhythm of the generated verse.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted user-supplied data, including poem drafts, character descriptions, and chapter content. This data is ingested to perform scansion, rhyme analysis, and stylistic revisions. The workflow involves reading character voice notes and chapter files to ensure verse consistency. While the skill lacks explicit boundary markers for this data, the shell commands are primarily static or scoped to project metadata, minimizing exploitation risk.
  • [PRIVILEGE_ESCALATION]: The instructions mention checking for the presence of text-to-speech software and suggest asking the user before attempting to install any missing utilities. This behavior is mediated by a requirement for user confirmation, which serves as a safeguard against unauthorized software installation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:19 AM
Security Audit — agent-trust-hub — verse-craft