writing-skills

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The utility script render-graphs.js executes the system dot command (Graphviz) to transform Graphviz descriptions into SVG images. Evidence:
  • The script uses execSync('dot -Tsvg', { input: dotContent }) to pass data safely via standard input (stdin), avoiding shell command injection risks.
  • The execution is restricted to the local dot utility and is intended for developer use in visualizing documentation flows.
  • [INDIRECT_PROMPT_INJECTION]: The skill framework establishes a protocol for agents to read, follow, and test instructions from external SKILL.md files, which represents an attack surface. Evidence:
  • The documentation provides a systematic approach for agents to process external markdown files while enforcing compliance through 'Red Flags' lists and rationalization tables.
  • The framework includes a verification cycle designed to prevent agents from disregarding safety guidelines when instructed to load and execute new skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:33 PM
Security Audit — agent-trust-hub — writing-skills