skills/howells/fiction/go/Gen Agent Trust Hub

go

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses dynamic context injection (the !command syntax) to run git log and cat progress.md. These commands are used to provide the agent with the recent state of the repository and project, representing normal development tool functionality.
  • [PROMPT_INJECTION]: The skill loads content from local files such as project documents and character sheets. While this creates a surface for indirect prompt injection if the files contain instructions, this is a standard risk for skills designed to analyze local data.
  • Ingestion points: README.md, themes.md, craft/tone.md, character/world files.
  • Boundary markers: Absent.
  • Capability inventory: Spawning subagents (fiction:reader-digest, fiction:next).
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 05:14 AM
Security Audit — agent-trust-hub — go