writing-skills

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a local utility script render-graphs.js used to render Graphviz (DOT) diagrams into SVG files. This script utilizes the child_process.execSync function to invoke the system's dot utility. The execution is localized to diagrams found within the skill's own documentation and is intended for visualization purposes during development.
  • [PROMPT_INJECTION]: The skill uses and teaches 'persuasion principles' (such as Authority and Commitment) and strict instructional 'Iron Laws' (e.g., 'Delete means delete') to ensure agents adhere to the TDD methodology. While these are potent behavioral instructions, they are focused on enforcing engineering discipline for skill creation and do not attempt to bypass global safety filters or extract system prompts.
  • [SAFE]: The skill's components, including the provided best practices and testing methodologies, align with established software engineering principles adapted for AI agent development. No evidence of data exfiltration, unauthorized remote downloads, or hidden obfuscation was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — writing-skills