writing-core

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user notes and source documentation (Ingestion). It enforces the use of the factual-kernel.md template as a boundary to separate raw input from generated prose (Boundaries). The skill's capabilities are limited to text generation, with no subprocess, network, or file-write operations defined within the skill's own code (Capabilities). The mandatory factual kernel workflow requires recording status and provenance for every claim, which serves as a robust sanitization process (Sanitization).
  • [EXTERNAL_DOWNLOADS]: The skill references advanced modules like executive-writing and business-case, which are vendor-owned resources belonging to the George-RD/growth-arsenal repository.
  • [COMMAND_EXECUTION]: Missing dependencies are resolved by instructing the agent to show the npx skills add command to the user, ensuring that all installation activity is transparent and human-verified rather than occurring silently.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 01:13 PM
Security Audit — agent-trust-hub — writing-core