calligraph-sensei

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security vulnerabilities, malicious patterns, or unauthorized activities were detected. The skill is composed of markdown-based instructions for styling and auditing text.
  • [PROMPT_INJECTION]: The skill identifies a potential indirect prompt injection surface as it is designed to ingest and process user-provided drafts.
  • Ingestion points: Workflow 1 in SKILL.md ('Ingestion & Analysis') processes external text or target files.
  • Boundary markers: Absent; there are no specific instructions in the provided files for the agent to use protective delimiters around user input.
  • Capability inventory: The skill is restricted to text processing within the LLM; no executable scripts, system calls, or network operations are included.
  • Sanitization: The references/audit_checklist.md provides a 'Semantic Preservation Audit' which requires the agent to verify that the output remains factually consistent with the original text, providing a safeguard against instruction-based hijacking.
  • [EXTERNAL_DOWNLOADS]: The documentation provides installation instructions via a GitHub repository (github.com/kshanxs/skill-dojo). This reference targets the author's official repository on a well-known service.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 01:16 AM
Security Audit — agent-trust-hub — calligraph-sensei