s4h-writing-scene-construction
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [NO_CODE]: The skill consists entirely of natural language instructions and YAML metadata. It does not include any scripts (Python, JavaScript, shell), binaries, or configuration files that execute commands.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote content. No use of
curl,wget, or package managers was detected. - [DATA_EXFILTRATION]: The skill does not perform any network operations or access sensitive local files. It does not contain any hardcoded credentials or API keys.
- [PROMPT_INJECTION]: The instructions are focused on providing a framework for story analysis. There are no attempts to bypass safety filters, override system prompts, or extract internal instructions.
- [COMMAND_EXECUTION]: The skill does not utilize any shell command execution or administrative privileges. It uses a standard interaction tool,
AskUserQuestion, to facilitate user input during the analysis process. - [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided text (story scenes), it lacks any high-privilege tools (such as file-writing, network access, or code execution) that could be exploited via malicious content in the processed data. The analysis surface is limited to providing feedback within the chat context.
Audit Metadata