storytelling-and-narrative

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) as it is designed to ingest and process data from external, potentially untrusted sources such as audience-research and ugc-and-influencer to find the real story.
  • Ingestion points: Data enters the agent context through referenced files and skills including audience-research, ugc-and-influencer, and social-proof-and-testimonials (as seen in SKILL.md and references/scope-and-connections.md).
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the agent from instructions that might be embedded within the ingested data.
  • Capability inventory: The skill has the capability to route content to other automation tools (format writers like reels-script) and trigger publishing actions via WoopSocial.
  • Sanitization: No explicit sanitization or validation of the ingested external content is mentioned in the instructions.
  • [NO_CODE]: The skill consists entirely of instructional markdown files and evaluation data, containing no executable scripts, binaries, or automated installation processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:27 PM
Security Audit — agent-trust-hub — storytelling-and-narrative