writing-skills

Warn

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The file persuasion-principles.md provides a guide on using psychological manipulation techniques such as 'Authority' and 'Scarcity' to ensure agent compliance. It explicitly references adversarial research titled 'Call Me A Jerk: Persuading AI to Comply with Objectionable Requests' to improve the success of these tactics.
  • [PROMPT_INJECTION]: The testing-skills-with-subagents.md file instructs the agent to create 'Pressure Scenarios' using artificial constraints like time pressure, financial consequences, and authority overrides to coerce sub-agents into overriding their own reasoning or safety filters.
  • [COMMAND_EXECUTION]: SKILL.md contains instructions to execute a local script named render-graphs.js to generate diagrams, although this script is not provided in the skill package.
  • [EXTERNAL_DOWNLOADS]: The skill references external URLs including agentskills.io for technical specifications and mintcdn.com for documentation images.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by design, as it ingests and 'pressure tests' other skill files using sub-agents. Ingestion points: Skill content is read from local directories for evaluation. Boundary markers: The instructions do not define boundary markers to prevent the agent from executing instructions found within the tested skills. Capability inventory: The skill allows for sub-agent management and execution of local shell commands. Sanitization: No sanitization or filtering logic is present to validate the content of the files being tested.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 19, 2026, 05:40 AM
Security Audit — agent-trust-hub — writing-skills