pre-write-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize content from multiple external files (.md and .json) within the workspace to maintain narrative consistency. This process introduces an attack surface where malicious instructions embedded in fiction data could influence agent behavior.
- Ingestion points: Reads content from nine distinct files including
memory/constitution.md,stories/*/specification.md, and various JSON tracking files inspec/tracking/. - Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' prompts when summarizing the ingested content.
- Capability inventory: The skill is restricted to
ReadandGreptools, limiting the potential impact of any injected instructions to the current conversation context. - Sanitization: No explicit sanitization or validation of the file content is performed beyond standard tool usage.
Audit Metadata