executive-writing

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external text ('factual kernels') to rewrite them into executive-style prose. This creates a processing surface for potential indirect instructions embedded in the input data. * Ingestion points: Input text provided to the agent for rewriting (referenced in Step 0 and Step 6). * Boundary markers: The skill does not define specific delimiters for untrusted input text. * Capability inventory: The skill is primarily instructional for text generation but directs the agent to interact with the environment for dependency installation via npx commands. * Sanitization: No explicit sanitization or filtering of input text is described.
  • [EXTERNAL_DOWNLOADS]: The skill identifies 'writing-core' and 'business-copy-style' as dependencies and provides commands to install them from the author's growth-arsenal repository. * Evidence: Step 0 and Step 6 provide the command 'npx skills add George-RD/growth-arsenal --skill [name]'. * The resources originate from the same vendor ('george-rd') as the skill itself.
  • [COMMAND_EXECUTION]: The skill instructs the agent to display or use npx commands for dependency management. * Evidence: 'npx skills add George-RD/growth-arsenal --skill writing-core' in SKILL.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:50 PM
Security Audit — agent-trust-hub — executive-writing