create-story
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill dynamically loads the taxonomy module from a relative filesystem path (
../taxonomy/taxonomy.py) usingimportlib.util. This allows for the execution of code based on filesystem structure. Additionally, it executes other local skills usingsubprocess.runvia theirrun.shscripts.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection by aggregating data from external research sources (web research viadogpileand library searches) and incorporating this untrusted content into prompts for the drafting phase.\n - Ingestion points: The initial creative
thoughtand research results fromdogpile,memory, andepisodic-archiver(documented inorchestrator.pyandstory_phases.py).\n - Boundary markers: Simple Markdown headers like
## Research Contextare used as delimiters instory_phases.py.\n - Capability inventory: The skill has the ability to execute other skills through
subprocess.runand perform file write operations.\n - Sanitization: Content is truncated but no robust sanitization or instruction-filtering is applied to the research data.\n- [DATA_EXFILTRATION]: The skill accesses and stores narrative details, character profiles, and tactical decision data across multiple memory scopes including
horus_lore,horus-stories, andagent_conversations(episodic archive). While data is stored locally, the broad recall scope across different contexts represents a data exposure risk.
Audit Metadata