writing-skills
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
render-graphs.jsscript utilizeschild_process.execSyncto run the systemdotcommand (part of Graphviz). It processes diagram content extracted from markdown blocks and passes it to the utility's standard input to generate SVG visualizations. - [PROMPT_INJECTION]: The skill methodology, specifically in
persuasion-principles.mdandtesting-skills-with-subagents.md, instructs the agent to use 'Authority' and 'Commitment' principles to ensure compliance with specified workflows. This includes the use of absolute directive language ('YOU MUST', 'No exceptions') and framing techniques like 'IMPORTANT: This is a real scenario' to prevent the model from deviating from instructions. These methods are structurally similar to techniques used in prompt injection research to override model reasoning, though they are applied here as a mechanism for process discipline. - [EXTERNAL_DOWNLOADS]: The documentation in
anthropic-best-practices.mdreferences external image assets hosted onmintcdn.com(associated with official Anthropic documentation) to provide visual examples for skill structure and bundling patterns.
Audit Metadata