go
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses dynamic context injection (the !command syntax) to run
git logandcat progress.md. These commands are used to provide the agent with the recent state of the repository and project, representing normal development tool functionality. - [PROMPT_INJECTION]: The skill loads content from local files such as project documents and character sheets. While this creates a surface for indirect prompt injection if the files contain instructions, this is a standard risk for skills designed to analyze local data.
- Ingestion points: README.md, themes.md, craft/tone.md, character/world files.
- Boundary markers: Absent.
- Capability inventory: Spawning subagents (fiction:reader-digest, fiction:next).
- Sanitization: Absent.
Audit Metadata