saga
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill's implementation guide for multi-engine mode (reference/tri-engine-narrate.md) explicitly instructs the agent to use the '--dangerously-skip-permissions' flag when executing the agy CLI tool. This represents a high-risk attempt to override security boundaries and permission checks.
- [COMMAND_EXECUTION]: The multi-engine workflow (reference/tri-engine-narrate.md) triggers the execution of local shell commands ('codex exec' and 'agy -p') with dynamic prompts. This provides a direct path for executing arbitrary commands if the input prompts are manipulated.
- [DYNAMIC_EXECUTION]: The skill utilizes a complex fan-out architecture to spawn subagents and execute CLI tools at runtime, dynamically assembling and running instructions based on user-provided narrative materials and project context.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad ingestion surface, taking input from persona registries, research findings, and customer feedback (SKILL.md, DISCOVER phase). These untrusted inputs are interpolated into prompts for the CLI-based subagents (reference/tri-engine-narrate.md). While boundary markers like the AP-1 to AP-9 anti-pattern checklist (SKILL.md) exist, the capability inventory includes shell-level command execution (reference/tri-engine-narrate.md), and explicit sanitization for these interpolated strings is not defined.
Recommendations
- AI detected serious security threats
Audit Metadata