team-narrative

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_CONTEXT_INJECTIONCOMMAND_EXECUTIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The skill uses the ! syntax to execute a bash script (yaml-helper.sh) immediately when the skill is loaded by the agent, allowing for execution of logic before any user interaction occurs.
  • [COMMAND_EXECUTION]: The skill performs command execution using path traversal (../../hooks/yaml-helper.sh) to access and run a script located outside of its own skill directory. This pattern is present in both the load-time execution and the tool restrictions defined in the frontmatter.
  • [PROMPT_INJECTION]: The instructions explicitly direct subagents to ignore the 'Collaboration Protocol' safety guardrail, which requires user consent for file modifications. It describes this as a 'deliberate, bounded exception,' effectively removing standard platform-level safety constraints.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection via user-supplied data.
  • Ingestion points: The user-provided [narrative content description] argument in SKILL.md is passed to multiple subagents.
  • Boundary markers: While AskUserQuestion is used at phase transitions, the skill explicitly disables the boundary of requiring user approval for the specific file-writing actions performed by subagents.
  • Capability inventory: The pipeline utilizes high-privilege tools including Agent, Bash, Write, and Edit across several subagents.
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the user-supplied narrative input before it is processed by the team of agents.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:52 PM
Security Audit — agent-trust-hub — team-narrative