create-story

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill dynamically loads the taxonomy module from a relative filesystem path (../taxonomy/taxonomy.py) using importlib.util. This allows for the execution of code based on filesystem structure. Additionally, it executes other local skills using subprocess.run via their run.sh scripts.\n- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection by aggregating data from external research sources (web research via dogpile and library searches) and incorporating this untrusted content into prompts for the drafting phase.\n
  • Ingestion points: The initial creative thought and research results from dogpile, memory, and episodic-archiver (documented in orchestrator.py and story_phases.py).\n
  • Boundary markers: Simple Markdown headers like ## Research Context are used as delimiters in story_phases.py.\n
  • Capability inventory: The skill has the ability to execute other skills through subprocess.run and perform file write operations.\n
  • Sanitization: Content is truncated but no robust sanitization or instruction-filtering is applied to the research data.\n- [DATA_EXFILTRATION]: The skill accesses and stores narrative details, character profiles, and tactical decision data across multiple memory scopes including horus_lore, horus-stories, and agent_conversations (episodic archive). While data is stored locally, the broad recall scope across different contexts represents a data exposure risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — create-story