writing-skills

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a Node.js utility script, render-graphs.js, which uses execSync to run system commands such as dot (Graphviz) and which. This script is designed to extract Graphviz diagrams from the skill documentation and render them as SVG files.- [DYNAMIC_EXECUTION]: The render-graphs.js script performs runtime file system operations, including reading SKILL.md files and writing rendered diagrams to a diagrams/ directory.- [EXTERNAL_DOWNLOADS]: The documentation (specifically anthropic-best-practices.md and SKILL.md) references several third-party libraries and tools, such as pdfplumber, pypdf, pytesseract, and graphviz, as examples for specific technical implementations.- [PROMPT_INJECTION]: The skill utilizes 'Persuasion Principles' (e.g., Authority, Commitment) and 'Bulletproofing' strategies to enforce strict adherence to developer workflows like TDD. These instructions use strong imperative language ("YOU MUST", "Delete means delete") to override the agent's internal reasoning or 'rationalization' during tasks, acting as a form of discipline enforcement rather than a malicious bypass of safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:01 AM
Security Audit — agent-trust-hub — writing-skills