story-lab

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The converge.py script executes shell commands via subprocess.run to orchestrate existing skills (create-story, review-story). These calls are limited to pre-defined entry points (run.sh) and do not accept arbitrary user-controlled shell input. The implementation explicitly clears the VIRTUAL_ENV environment variable to prevent environment poisoning across skill executions.
  • [DATA_EXPOSURE]: The skill implements a structured convergence loop that tracks creative quality metrics (voice, lore, craft). While it interacts with a /memory skill, there is no evidence of sensitive credential harvesting or exfiltration to external domains. Access is restricted to relative paths within the skill directory structure.
  • [PROMPT_INJECTION]: The skill incorporates specific creative writing rules (Horus persona, Theory of Mind checks) and enforces that all critique must come from an automated subprocess (/review-story) rather than bespoke NLP. This architectural choice limits the surface area for direct or indirect prompt injection by decoupling evaluation from the generation prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — story-lab