create-stories
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill executes a shell command at load time using the
!syntax to resolve configuration parameters. - Evidence:
!bash "${CLAUDE_SKILL_DIR}/../../hooks/yaml-helper.sh" resolve_config --keys review_mode,automation,workflow,docs.density,story_granularity,system_overridesinSKILL.md. - This is a project-specific tool used for environment configuration and does not interact with sensitive system files or network resources.
- [COMMAND_EXECUTION]: The skill is authorized to execute a specific bash script for configuration management.
- Evidence: The
allowed-toolsfrontmatter restrictsBashto theyaml-helper.shscript located relative to the skill directory. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple design and architecture files which could potentially contain malicious instructions.
- Ingestion points: The skill reads
design/gdd/[filename].md,docs/architecture/[adr-file].md,docs/architecture/control-manifest.md, anddocs/architecture/tr-registry.yamlas part of Step 2. - Boundary markers: The skill utilizes structured parsing, including
Grepwith context andReadwith specific byte offsets and limits, which provides some structural isolation. However, it lacks explicit safety delimiters to warn the agent about embedded instructions in the ingested text. - Capability inventory: The skill has the ability to write new markdown files to the repository (
Write) and spawn a secondary agent (Agentforqa-lead). - Sanitization: There is no evidence of content sanitization or filtering of the requirement text before it is interpolated into the generated story files.
Audit Metadata