write
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Node.js scripts (
scripts/run-state-check.jsandskills/write/scripts/lint.js) to process text. These scripts use standard Node.js modules (fs,path) to read local files (rules.json,draft.md) or standard input. No arbitrary command injection or remote code execution vectors were found. - [PROMPT_INJECTION]: The skill instructions include clear boundary markers and safety guidelines for the AI agent (e.g., 'Do not invent a personality', 'Refuse to claim the draft is undetectable'). These instructions are designed to maintain authenticity rather than bypass safety filters.
Audit Metadata