technical-writing

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes scripts/verify.sh, a bash utility that uses grep to scan documentation files for a hardcoded list of 'weasel words' (e.g., 'simply', 'just'). The script is a read-only tool intended for local linting by the agent to ensure prose quality.
  • [EXTERNAL_DOWNLOADS]: The skill references established industry resources including the Google Developer Documentation Style Guide, the Diátaxis framework (diataxis.fr), and the Vale prose linter (vale.sh). It provides a sample GitHub Actions configuration that references the official errata-ai/vale-action@reviewdog action for automated CI linting.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and restructure technical documents provided by users.
  • Ingestion points: Technical documentation files (Markdown/reStructuredText) processed by the agent or passed as arguments to the scripts/verify.sh script.
  • Boundary markers: The skill enforces strict structural boundaries by requiring all documentation to fit exactly one of four Diátaxis modes (Tutorial, How-to, Reference, or Explanation).
  • Capability inventory: The skill's automated capability is limited to local file system read access for linting purposes. It does not perform network operations or execute arbitrary shell commands based on document content.
  • Sanitization: The prose verification script uses static regex patterns against a fixed, hardcoded banlist to validate content, preventing data from influencing the script's execution logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — technical-writing