tavern-card-builder

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill framework facilitates the extraction and processing of content from source materials like novels, notes, and chat logs to build agent logic (Chain-of-Thought) and state-update rules. This ingestion of external data represents an indirect prompt injection surface.\n
  • Ingestion points: Found in references/material-provenance.md where a pipeline is described for extracting "material fragments" from external source files (novels, notes, chat exports) into claims and card entries.\n
  • Boundary markers: The architecture uses logical stable IDs for tracking provenance but lacks technical delimiters (such as XML tags or explicit "ignore instructions" tokens) to prevent the agent from obeying commands embedded in the source fragments.\n
  • Capability inventory: The skill facilitates the creation of behavioral protocols (CoT), script requirements, and state-update logic, all of which determine how the agent interprets and reacts to the ingested narrative data.\n
  • Sanitization: The methodology relies on manual "creative reconciliation" and "fidelity review" passes rather than technical sanitization or automated filtering of the external text inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 08:37 AM
Security Audit — agent-trust-hub — tavern-card-builder