writing-skills
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes a local utility script
render-graphs.jsused to render Graphviz (DOT) diagrams into SVG files. This script utilizes thechild_process.execSyncfunction to invoke the system'sdotutility. The execution is localized to diagrams found within the skill's own documentation and is intended for visualization purposes during development. - [PROMPT_INJECTION]: The skill uses and teaches 'persuasion principles' (such as Authority and Commitment) and strict instructional 'Iron Laws' (e.g., 'Delete means delete') to ensure agents adhere to the TDD methodology. While these are potent behavioral instructions, they are focused on enforcing engineering discipline for skill creation and do not attempt to bypass global safety filters or extract system prompts.
- [SAFE]: The skill's components, including the provided best practices and testing methodologies, align with established software engineering principles adapted for AI agent development. No evidence of data exfiltration, unauthorized remote downloads, or hidden obfuscation was found.
Audit Metadata