worldbuilding
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions in
SKILL.mdrepeatedly direct the agent to execute shell commands using thestoryCLI tool. These instructions interpolate user-provided values directly into shell strings. - Evidence in
SKILL.md(Creating a Location):story names "{Candidate}"andstory add location "{Location Name}" --type "{type}". - Evidence in
SKILL.md(Creating A Faction):story add faction "{Faction Name}" --type "{...}". - Evidence in
SKILL.md(Creating An Artifact):story add artifact "{Artifact Name}" --type "{...}". - This pattern allows for command injection if a user provides a name containing shell metacharacters (e.g.,
"; rm -rf /; "). - [DYNAMIC_EXECUTION]: The skill provides a fallback mechanism for execution when the primary CLI is not installed, instructing the agent to run a JavaScript file from a relative path outside the skill's own directory.
- Evidence in
SKILL.md: "use the bundled fallbacknode ../story-maintenance/scripts/story.jswith the same arguments". - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external markdown files which could contain untrusted data that influences the agent's behavior.
- Ingestion points: The agent reads
story.md,worldbuilding/_index.md, and various element files in theworldbuilding/directory. - Boundary markers: There are no instructions for the agent to use delimiters or ignore instructions embedded within the ingested worldbuilding files.
- Capability inventory: The skill has significant capabilities including file system writes and shell command execution via the
storyCLI. - Sanitization: The skill lacks instructions for sanitizing or escaping content read from files or provided by the user before it is used in logic or shell commands.
Audit Metadata