readme-writing-weapon
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of educational Markdown guides, templates, and research summaries. No executable scripts, binaries, or active code components are included in the package.
- [PROMPT_INJECTION]: Analysis of the instructional text found no attempts to bypass safety filters, override system prompts, or implement jailbreak-style commands. The instructions are strictly focused on README structural discipline.
- [COMMAND_EXECUTION]: There are no shell commands, subprocess calls, or instances of the dynamic context injection syntax (
!command) detected in any of the analyzed files. - [DATA_EXFILTRATION]: While the templates for internal tools include placeholders for documenting where to find credentials (e.g., 1Password vaults), this is standard practice for internal engineering documentation. No automated logic exists to access, read, or transmit sensitive files like
.envor.ssh/config. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data (existing README files) for auditing and rewriting. This creates a standard surface for indirect prompt injection (Category 8). However, the risk is mitigated by the skill's use of a prescriptive 12-point checklist and a strict canonical section order, which provide strong structural boundaries for the AI's output.
Audit Metadata