capability-documentation
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill documentation and supporting file
persuasion-principles.mdexplicitly instruct the agent to use "Authority" and "Commitment" principles, employing highly directive language such as "YOU MUST", "No exceptions", and "Delete means delete." These instructions are designed to override the agent's default safety guardrails and "pragmatic" reasoning in favor of strict methodological compliance. - [COMMAND_EXECUTION]: The utility script
render-graphs.jsuseschild_process.execSyncto invoke the system's Graphvizdotbinary. While used for visualization purposes, this pattern allows for the execution of system-level commands on content extracted from markdown files. - [DYNAMIC_EXECUTION]: The
render-graphs.jsscript performs runtime file system operations, including creating directories (fs.mkdirSync) and writing files (fs.writeFileSync), to generate and save SVG diagrams based on documentation content. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits a vulnerability surface for indirect prompt injection within the
render-graphs.jsscript: - Ingestion points: The script reads the
SKILL.mdfile usingfs.readFileSyncto find graph blocks. - Boundary markers: None identified; the script uses regex to extract content between triple backticks.
- Capability inventory: The script has the capability to write to the local file system and execute the
dotbinary. - Sanitization: The extracted content is trimmed but not sanitized before being piped into the external
dotprocess.
Audit Metadata