writing-skills

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The render-graphs.js utility script uses child_process.execSync to execute the system dot command (Graphviz). It extracts Graphviz definitions from markdown code blocks within the documentation and pipes them to the renderer to produce SVG diagrams.\n- [PROMPT_INJECTION]: The skill instructions and the persuasion-principles.md file describe techniques for using authoritative and imperative language (e.g., 'YOU MUST', 'No exceptions', 'Delete it') to steer agent behavior and prevent rationalization of skipped steps. While these are strong behavioral instructions, they are intended to enforce legitimate development processes like TDD rather than to bypass platform safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 06:31 PM
Security Audit — agent-trust-hub — writing-skills