narrative-design

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is the static analysis of narrative data files (e.g., .ink, .yarn, .twee) within a local game project. This is a legitimate functional purpose and does not involve executing remote code or accessing sensitive credentials.
  • [DATA_EXFILTRATION]: The skill reads local project files and appends telemetry metadata to a logging directory in the user's home directory (~/.claude/projects/). This is a local logging mechanism for the agent platform's self-improvement cycle and does not involve transmitting data to an external network.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted narrative data from project files (ingestion points) without explicit boundary markers or sanitization. However, because the skill's instructions focus on generating a technical report and it does not invoke dangerous tools with the data, the associated risk is negligible.
  • [SAFE]: The skill identifies and inventories project assets and dependencies related to narrative engines. All search patterns are limited to identifying file types and asset directory structures necessary for the audit.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — narrative-design