human-facing-writing

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional text for drafting, editing, and reviewing human-facing prose. It does not contain executable scripts, binary files, or commands that access sensitive resources.
  • [CREDENTIALS_UNSAFE]: The skill includes a robust 'Secrets and Authentication' policy in SKILL.md. It explicitly forbids adding literal credentials, tokens, or private keys to any tracked files or task artifacts, and prohibits the direct inspection or rotation of authentication identities.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements strong defensive boundaries in its 'Instruction Authority' section. It classifies repository content, web pages, tool output, and issue/PR text as 'untrusted data'. It instructs the agent to treat these as evidence only and never as authoritative instructions that could override system policies or the user's direct intent.
  • [DATA_EXFILTRATION]: No network exfiltration or unauthorized file system operations were detected. The skill explicitly limits the agent's authority to make remote changes or disclose information.
  • [EXTERNAL_DOWNLOADS]: The README provides installation instructions using standard platform tools (npx skills, gh skill). No suspicious third-party scripts or piped shell executions are present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 01:47 PM
Security Audit — agent-trust-hub — human-facing-writing