writing-skills

Warn

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The render-graphs.js utility script uses child_process.execSync to execute the system command dot. This command is passed content extracted directly from SKILL.md files as input. This execution pattern presents a risk if the processed markdown contains malicious Graphviz code designed to exploit the renderer or the host shell.
  • [PROMPT_INJECTION]: The skill and its associated documentation (persuasion-principles.md, testing-skills-with-subagents.md) describe methods to enforce agent compliance by overriding its standard 'rationalization' processes. It instructs on the use of 'Authority' and 'Commitment' principles, which involve using imperative, non-negotiable language (e.g., 'YOU MUST', 'No exceptions') and framing scenarios to bypass an agent's internal autonomy and heuristics.
  • [EXTERNAL_DOWNLOADS]: The documentation (specifically anthropic-best-practices.md) contains links to external documentation and image assets hosted on platform.claude.com and mintcdn.com. These are recognized as well-known technology and cloud service domains and do not contribute to verdict escalation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 11:34 PM
Security Audit — agent-trust-hub — writing-skills