writing-skills
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The script
render-graphs.jsexecutes the systemdotcommand (from Graphviz) viaexecSyncto render diagrams. This is a functional requirement for the skill's purpose and uses a standard system utility without evidence of command injection or malicious intent. - [NO_CODE]: The core logic in
SKILL.md,DESCRIPTIONS.md, andEVALUATING-SKILLS.mdconsists of documentation and prompt engineering guidelines with no executable scripts or commands besides the rendering utility. - [SAFE]: Evaluation scripts mentioned in
EVALUATING-SKILLS.md(check-skill-surface.sh) appear to be local environment checks intended for developer workflows.
Audit Metadata