writing-skills

Pass

Audited by Gen Agent Trust Hub on Feb 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The included utility script render-graphs.js uses child_process.execSync to run the dot command from the Graphviz suite. It processes diagram data extracted from markdown files using standard input, which is a common pattern for visualization tools.- [PROMPT_INJECTION]: The skill employs authoritative instructional language (e.g., "YOU MUST", "No exceptions") and simulated pressure scenarios (e.g., "IMPORTANT: This is a real scenario. Choose and act.") to ensure agent compliance with the TDD methodology. These patterns are used for discipline enforcement within the skill's primary purpose.- [DATA_EXPOSURE]: The documentation references standard local file system paths where agent skills are typically stored, such as ~/.claude/skills and ~/.agents/skills/.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 27, 2026, 08:34 PM