writing-skills

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script "render-graphs.js" executes the system commands "dot" and "which" using "child_process.execSync". This is used to render diagrams from markdown content provided by the user.
  • [COMMAND_EXECUTION]: Documentation files like "SKILL.md" and "anthropic-best-practices.md" contain examples of shell commands (e.g., "ls", "grep", "pip install") intended for manual or agent-assisted project management.
  • [PROMPT_INJECTION]: The skill includes documentation on using "Authority" principles and imperative language (e.g., "YOU MUST", "No exceptions") to ensure process compliance. These are pedagogical patterns for skill authoring and do not attempt to bypass agent safety constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 05:09 AM
Security Audit — agent-trust-hub — writing-skills