writing-skills
Warn
Audited by Gen Agent Trust Hub on Feb 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- COMMAND_EXECUTION (MEDIUM): The script
render-graphs.jsutilizesexecSyncto invoke the Graphvizdotutility. It extracts content fromSKILL.mdand passes it directly to the process stdin. While intended for diagram rendering, the use ofexecSyncon content derived from data files constitutes a risk of command injection or unauthorized execution if the input files are maliciously modified.\n- PROMPT_INJECTION (LOW): The filespersuasion-principles.mdandexamples/CLAUDE_MD_TESTING.mdcontain instructions and emphatic prompt templates (e.g., Variant C) designed to override an agent's reasoning. These patterns use 'Authority' and 'Commitment' techniques (e.g., 'THIS IS EXTREMELY IMPORTANT', 'you failed') to force compliance and bypass standard agent decision-making filters.
Audit Metadata