create-story

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands like git log and git diff to analyze repository history and gather context for story creation.
  • [COMMAND_EXECUTION]: It employs the GitHub CLI (gh) and custom bash scripts (set-github-project-priority.sh) to interact with remote project boards and manage issue metadata.
  • [EXTERNAL_DOWNLOADS]: The skill performs authorized network requests to Jira and GitHub APIs to synchronize story data and create tracker issues. These operations use user-configured environment variables for authentication.
  • [REMOTE_CODE_EXECUTION]: A utility script (resolve-platform.sh) executes a small Python snippet via python -c to parse YAML configuration files. This is a localized and safe use of dynamic execution for configuration processing.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes PRDs and architecture files which are external data sources. However, it mitigates this through a mandatory 'Anti-Hallucination Protocol'.
  • Ingestion points: Reading sharded PRD files, architecture documents, and git commit history (SKILL.md Steps 2 and 3).
  • Boundary markers: The skill requires all technical details to be wrapped in specific source citations (e.g., [Source: architecture/filename.md#section]).
  • Capability inventory: Local file writes (stories and plans), YAML updates to sprint-status.yaml, and remote issue creation via Jira/GitHub APIs.
  • Sanitization: Strictly forbids the 'invention' of technical details and requires every claim to be traceable to a source document.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — create-story