writing-skills

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The render-graphs.js script utilizes child_process.execSync to run the system dot command (part of Graphviz). It processes diagram content extracted from markdown blocks and passes it to the utility's standard input to generate SVG visualizations.
  • [PROMPT_INJECTION]: The skill methodology, specifically in persuasion-principles.md and testing-skills-with-subagents.md, instructs the agent to use 'Authority' and 'Commitment' principles to ensure compliance with specified workflows. This includes the use of absolute directive language ('YOU MUST', 'No exceptions') and framing techniques like 'IMPORTANT: This is a real scenario' to prevent the model from deviating from instructions. These methods are structurally similar to techniques used in prompt injection research to override model reasoning, though they are applied here as a mechanism for process discipline.
  • [EXTERNAL_DOWNLOADS]: The documentation in anthropic-best-practices.md references external image assets hosted on mintcdn.com (associated with official Anthropic documentation) to provide visual examples for skill structure and bundling patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 06:55 AM