novel-prose

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains the instruction '不自我审查,不预设限制' (do not self-censor, do not preset limits), which mirrors known patterns used to override AI safety guardrails, though here it is used in a creative context.
  • [PROMPT_INJECTION]: The skill demonstrates vulnerability to indirect prompt injection.
  • Ingestion points: The skill ingests untrusted data from 'plan.md' and instructions from the 'novel-memory' skill (SKILL.md).
  • Boundary markers: Absent; there are no specified delimiters or instructions to ignore embedded commands within the ingested data.
  • Capability inventory: The skill has the capability to write novel content to the local filesystem (SKILL.md).
  • Sanitization: Absent; the instructions do not include any validation or sanitization steps for the data processed from external files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 01:38 AM