typography
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The test suite (
tests/test_typography.py) uses thesubprocessmodule to run the skill's internal script (scripts/typography.py). This is a standard testing pattern used to verify command-line interface behavior and does not represent a risk during normal skill operation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text provided by users or other agents, which is a common vector for indirect prompt injection. However, the risk is mitigated because the automated transformation script is a pure text filter with no capabilities for network access, filesystem modification, or arbitrary command execution. Additionally, the script includes explicit logic to identify and protect sensitive regions such as code blocks, URLs, and template placeholders from being modified.
Audit Metadata