short-drama-review
Warn
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires the agent to run Python scripts (
novel_index.py,suite_verify.py, andproject_tool.py) located in sibling directories or the 'core' skill path. These scripts are used to verify installation integrity and perform coverage analysis on project files. - [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted text artifacts, such as screenplays and novel analyses, which constitutes an indirect prompt injection surface. The workflow includes safeguards like 'fresh reviewer contexts' to mitigate bias, but the ingestion of external data remains a point of interest.
- [DATA_EXFILTRATION]: The skill accesses and processes sensitive project data across multiple layers (story, script, assets). While no network transmission to untrusted domains is detected, the skill has extensive read access to project artifacts to provide evidence for its findings.
Audit Metadata