team-narrative
Pass
Audited by Gen Agent Trust Hub on Apr 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. It ingests untrusted data through the user-provided argument
[narrative content description]and processes existing project data viaRead,Glob, andGreptools. This information is interpolated into prompts for subagents (Tasktool) without the use of explicit boundary markers, delimiters, or instructions to ignore embedded commands. While the requirement for user approval viaAskUserQuestionat each phase transition serves as a mitigation, the lack of input sanitization or delimited context means malicious instructions hidden in story briefs or lore files could potentially influence the logic of the narrative team agents. The primary risk involves the subagents' capabilities toWriteandEditfiles based on the processed narrative data.
Audit Metadata