writing-skills

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The provided render-graphs.js utility executes the system command dot (part of the Graphviz suite) using Node.js's execSync. This is used to transform markdown-embedded dot blocks into SVG diagrams for visualization. The command execution is performed on data extracted from local files and uses standard input (stdin) for the diagram content, which is a secure implementation pattern.
  • [PROMPT_INJECTION]: The documentation files persuasion-principles.md and testing-skills-with-subagents.md include meta-instructions on how to design prompts that override an agent's tendency to rationalize away from disciplinary protocols (like TDD). While these techniques involve using authoritative and imperative language typically associated with behavioral influence, they are presented as educational guidelines for building reliable, self-enforcing skill documentation and do not target the platform's safety guardrails or user interests.
  • [EXTERNAL_DOWNLOADS]: The anthropic-best-practices.md file contains references to well-known Python packages such as pdfplumber, pypdf, pdf2image, and pytesseract as examples of tool usage. These are standard libraries from established repositories and are documented neutrally for educational purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 10:13 AM
Security Audit — agent-trust-hub — writing-skills