better-writing
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill includes Python scripts (
scripts/scan_aiisms.py,scripts/probe_better_writing.py) for diagnostic text analysis. These scripts are self-contained, use only standard libraries, and perform no network requests or sensitive file access. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted user-supplied prose. It incorporates a robust 'Operating Contract' and 'Fidelity Gate' that explicitly instruct the agent to preserve technical identifiers, commands, and code byte-for-byte as literals. This minimizes the risk of the agent misinterpreting input data as instructions.
- [SAFE]: External URLs referenced in the research notes and documentation are informational and link to trusted domains such as arxiv.org, reuters.com, and developers.google.com.
- [COMMAND_EXECUTION]: The skill suggests the execution of its own utility scripts for scanning drafts. This is a legitimate functional capability and is implemented without dangerous shell features.
Audit Metadata