skills/av/skills/mosaic-writing/Gen Agent Trust Hub

mosaic-writing

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill follows established patterns for text processing and orchestration.
  • [COMMAND_EXECUTION]: The skill executes local utility scripts (lint.sh and frequency.py) and references a sibling skill (catalog-deslop) for text refinement. These are vendor-provided components within the same suite.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles user-provided text fragments as primary input. It includes a multi-stage review process (Cold Reviewer) that specifically checks for 'fidelity' and 'coverage', which serves to ensure the agent follows the structure of the fragments rather than potential instructions embedded within them. 1. Ingestion points: User-provided fragments.md file. 2. Boundary markers: Markdown beat headings are used to separate input sections. 3. Capability inventory: File system writes via standard tools, shell script execution for linting, and git commits for final output. 4. Sanitization: The skill relies on the fidelity contract and reviewer sub-agents to validate output against source fragments instead of programmatic sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 03:25 PM
Security Audit — agent-trust-hub — mosaic-writing