story-lab
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The
converge.pyscript executes shell commands viasubprocess.runto orchestrate existing skills (create-story,review-story). These calls are limited to pre-defined entry points (run.sh) and do not accept arbitrary user-controlled shell input. The implementation explicitly clears theVIRTUAL_ENVenvironment variable to prevent environment poisoning across skill executions. - [DATA_EXPOSURE]: The skill implements a structured convergence loop that tracks creative quality metrics (voice, lore, craft). While it interacts with a
/memoryskill, there is no evidence of sensitive credential harvesting or exfiltration to external domains. Access is restricted to relative paths within the skill directory structure. - [PROMPT_INJECTION]: The skill incorporates specific creative writing rules (Horus persona, Theory of Mind checks) and enforces that all critique must come from an automated subprocess (
/review-story) rather than bespoke NLP. This architectural choice limits the surface area for direct or indirect prompt injection by decoupling evaluation from the generation prompt.
Audit Metadata