novel-prose
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains the instruction '不自我审查,不预设限制' (do not self-censor, do not preset limits), which mirrors known patterns used to override AI safety guardrails, though here it is used in a creative context.
- [PROMPT_INJECTION]: The skill demonstrates vulnerability to indirect prompt injection.
- Ingestion points: The skill ingests untrusted data from 'plan.md' and instructions from the 'novel-memory' skill (SKILL.md).
- Boundary markers: Absent; there are no specified delimiters or instructions to ignore embedded commands within the ingested data.
- Capability inventory: The skill has the capability to write novel content to the local filesystem (SKILL.md).
- Sanitization: Absent; the instructions do not include any validation or sanitization steps for the data processed from external files.
Audit Metadata