avoid-ai-writing-router
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust orchestration model with a defined 'handoff contract' and 'authority chain' to prevent logic errors and maintain consistency across different processing stages.
- [COMMAND_EXECUTION]: The file
scripts/validate_connections.test.pyusessubprocess.runto execute a companion validation script (validate_connections.py). This is a benign use for automated testing during development, as it only executes local Python scripts within the skill's own directory using controlled arguments. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface as it processes user-provided text and files for auditing and rewriting.
- Ingestion points: Untrusted data enters the context through the
handoff-contract.mdenvelope (pasted_text, named_file, visual_prompt). - Boundary markers: The skill defines explicit 'Return-to-router' semantics and 'Ownership rules' to isolate decision classes and prevent downstream skills from overriding upstream decisions.
- Capability inventory: The network includes signal collection, file mutation (in-place editing), and verification capabilities.
- Sanitization: The orchestrator enforces 'Review lenses' (software architect, AI engineer, senior developer) to validate the graph integrity and evidence semantics, ensuring the agent operates within defined safety and editorial boundaries.
Audit Metadata