pre-write-checklist

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize content from multiple external files (.md and .json) within the workspace to maintain narrative consistency. This process introduces an attack surface where malicious instructions embedded in fiction data could influence agent behavior.
  • Ingestion points: Reads content from nine distinct files including memory/constitution.md, stories/*/specification.md, and various JSON tracking files in spec/tracking/.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' prompts when summarizing the ingested content.
  • Capability inventory: The skill is restricted to Read and Grep tools, limiting the potential impact of any injected instructions to the current conversation context.
  • Sanitization: No explicit sanitization or validation of the file content is performed beyond standard tool usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 10:36 AM
Security Audit — agent-trust-hub — pre-write-checklist