writing-skills
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill explicitly teaches and utilizes behavior override techniques based on psychological principles such as 'Authority', 'Commitment', and 'Scarcity' to ensure agent compliance even when the agent's internal logic might suggest otherwise. It includes instructions to suppress 'rationalization' (the agent's reasoning or judgment) and uses non-negotiable framing like 'Violating the letter is violating the spirit' and 'Delete means delete' to bypass safety-relevant reasoning and force compliance with documented rules.
- [COMMAND_EXECUTION]: The skill includes a Node.js utility script,
render-graphs.js, which useschild_process.execSyncto run system commands includingdot -Tsvgandwhich dot. Additionally, the skill's documentation (SKILL.md) provides instructions for the agent to execute this script and other shell commands. - [EXTERNAL_DOWNLOADS]: The documentation file
anthropic-best-practices.mdcontains instructions for the agent to download and install external software packages from public registries at runtime, such aspip install pypdfandpip install pdfplumber. - [DYNAMIC_EXECUTION]: The
render-graphs.jsscript dynamically extracts DOT graph definitions fromSKILL.mdand pipes them as input to the system'sdotcommand. This pattern of processing file content into system subprocesses creates a risk where malicious or malformed graph definitions could exploit the underlying rendering engine.
Recommendations
- AI detected serious security threats
Audit Metadata