li-multi-event-twist-story

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs automated file system operations, specifically reading from and writing to a local database at ~/.li/个人故事库.md. These operations allow the skill to persist user-provided stories and personal details across multiple sessions.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from a local file. 1. Ingestion points: The agent reads the complete contents of the user's story database file (~/.li/个人故事库.md) to generate scripts. 2. Boundary markers: The instructions provide no specific delimiters or ignore-instructions warnings to isolate the story content from the generation prompt. 3. Capability inventory: The skill utilizes file reading, file writing, and natural language generation tools. 4. Sanitization: No content filtering or validation is performed on the data retrieved from storage before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 10:38 AM
Security Audit — agent-trust-hub — li-multi-event-twist-story