writing-skills

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The file render-graphs.js is a local utility script that uses Node.js child_process.execSync to run the system's dot command. This is used to transform Graphviz diagrams embedded in documentation into SVG files. The implementation is secure as it passes the diagram content through standard input (stdin) rather than command-line arguments, preventing shell injection vulnerabilities.
  • [PROMPT_INJECTION]: The persuasion-principles.md file discusses the use of forceful language (e.g., "YOU MUST", "No exceptions") to ensure agents adhere to strict project-level rules like TDD. These are instructional techniques aimed at improving operational reliability rather than attempts to bypass the underlying LLM's safety guardrails or ethical constraints.
  • [SAFE]: All external links provided in the documentation (e.g., to anthropic.com or well-known documentation CDNs) are legitimate. The skill is entirely focused on providing a meta-framework for skill development and contains no patterns for data exfiltration, credential harvesting, or malicious persistence.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 03:42 AM