skills/howells/fiction/review/Gen Agent Trust Hub

review

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user-controlled manuscript chapters and character documentation, creating a surface for indirect prompt injection attacks. \n
  • Ingestion points: manuscript chapters (e.g., 'chapters/08.md'), character documents, and project tone guides are read from the local file system. \n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when the agent processes the content of these external files. \n
  • Capability inventory: The skill has the ability to write to the file system (e.g., 'review-report.md') and spawn sub-agents using the Task tool. \n
  • Sanitization: There is no evidence of sanitization or input validation for the manuscript content before it is provided to the agent for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 05:14 AM
Security Audit — agent-trust-hub — review