capability-documentation

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill documentation and supporting file persuasion-principles.md explicitly instruct the agent to use "Authority" and "Commitment" principles, employing highly directive language such as "YOU MUST", "No exceptions", and "Delete means delete." These instructions are designed to override the agent's default safety guardrails and "pragmatic" reasoning in favor of strict methodological compliance.
  • [COMMAND_EXECUTION]: The utility script render-graphs.js uses child_process.execSync to invoke the system's Graphviz dot binary. While used for visualization purposes, this pattern allows for the execution of system-level commands on content extracted from markdown files.
  • [DYNAMIC_EXECUTION]: The render-graphs.js script performs runtime file system operations, including creating directories (fs.mkdirSync) and writing files (fs.writeFileSync), to generate and save SVG diagrams based on documentation content.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection within the render-graphs.js script:
  • Ingestion points: The script reads the SKILL.md file using fs.readFileSync to find graph blocks.
  • Boundary markers: None identified; the script uses regex to extract content between triple backticks.
  • Capability inventory: The script has the capability to write to the local file system and execute the dot binary.
  • Sanitization: The extracted content is trimmed but not sanitized before being piped into the external dot process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — capability-documentation