writing-skills

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill 'writing-skills' is a meta-documentation project focused on improving the quality and reliability of agent instructions through a structured TDD process. The content consists primarily of instructional material, best practices, and psychological principles for agent compliance.
  • [COMMAND_EXECUTION]: The skill includes a utility script render-graphs.js which uses Node.js execSync to invoke the Graphviz dot utility. The script is intended for use by the agent or user to visualize documentation flows. The execution is handled securely by passing diagram data through stdin rather than shell arguments, and the output path is restricted to a 'diagrams' subdirectory, mitigating risks of command injection or arbitrary file writes.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a methodology for testing agent compliance using 'pressure scenarios'. While these involve authoritative language meant to influence agent behavior, they are legitimate design patterns for ensuring rule adherence in complex workflows and do not constitute an adversarial attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — writing-skills