team-narrative
Warn
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill uses the
!syntax to execute a bash script (yaml-helper.sh) immediately when the skill is loaded by the agent, allowing for execution of logic before any user interaction occurs. - [COMMAND_EXECUTION]: The skill performs command execution using path traversal (
../../hooks/yaml-helper.sh) to access and run a script located outside of its own skill directory. This pattern is present in both the load-time execution and the tool restrictions defined in the frontmatter. - [PROMPT_INJECTION]: The instructions explicitly direct subagents to ignore the 'Collaboration Protocol' safety guardrail, which requires user consent for file modifications. It describes this as a 'deliberate, bounded exception,' effectively removing standard platform-level safety constraints.
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection via user-supplied data.
- Ingestion points: The user-provided
[narrative content description]argument inSKILL.mdis passed to multiple subagents. - Boundary markers: While
AskUserQuestionis used at phase transitions, the skill explicitly disables the boundary of requiring user approval for the specific file-writing actions performed by subagents. - Capability inventory: The pipeline utilizes high-privilege tools including
Agent,Bash,Write, andEditacross several subagents. - Sanitization: There is no evidence of sanitization, validation, or escaping of the user-supplied narrative input before it is processed by the team of agents.
Audit Metadata