fanqie-novel-skill
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of instructional documentation and data templates in Markdown and JSON formats. It does not contain any executable scripts, shell commands, or external dependencies.
- [INDIRECT_PROMPT_INJECTION]: The skill includes a 'handoff' mechanism that ingests data from a file named
handoff_current.mdto maintain session continuity. While this represents a data ingestion surface, the skill is intended for creative writing and lacks access to sensitive capabilities or system tools that could be abused via malicious content in the handoff file. Evidence: Ingestion point athandoff_current.mdused for state management; no command execution or network capabilities inventory found. - [DATA_EXPOSURE]: All data management (e.g., world building, character arcs, progress tracking) is performed within the project's local markdown files. There are no patterns indicating the exfiltration of credentials or sensitive environment data.
Audit Metadata