writing-skills
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The utility script
render-graphs.jsexecutes the systemdotcommand (Graphviz) to transform Graphviz descriptions into SVG images. Evidence: - The script uses
execSync('dot -Tsvg', { input: dotContent })to pass data safely via standard input (stdin), avoiding shell command injection risks. - The execution is restricted to the local
dotutility and is intended for developer use in visualizing documentation flows. - [INDIRECT_PROMPT_INJECTION]: The skill framework establishes a protocol for agents to read, follow, and test instructions from external
SKILL.mdfiles, which represents an attack surface. Evidence: - The documentation provides a systematic approach for agents to process external markdown files while enforcing compliance through 'Red Flags' lists and rationalization tables.
- The framework includes a verification cycle designed to prevent agents from disregarding safety guidelines when instructed to load and execute new skills.
Audit Metadata