writing-skills

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script render-graphs.js executes the system dot command (from Graphviz) via execSync to render diagrams. This is a functional requirement for the skill's purpose and uses a standard system utility without evidence of command injection or malicious intent.
  • [NO_CODE]: The core logic in SKILL.md, DESCRIPTIONS.md, and EVALUATING-SKILLS.md consists of documentation and prompt engineering guidelines with no executable scripts or commands besides the rendering utility.
  • [SAFE]: Evaluation scripts mentioned in EVALUATING-SKILLS.md (check-skill-surface.sh) appear to be local environment checks intended for developer workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 12:33 PM
Security Audit — agent-trust-hub — writing-skills