writing-skills
Pass
Audited by Gen Agent Trust Hub on Mar 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The utility
render-graphs.jsutilizesexecSyncto invoke the localdotbinary (from the Graphviz suite). This facilitates the rendering of Graphviz diagrams embedded in markdown files into SVG format. The command is strictly limited to thedot -Tsvginvocation with inputs provided via standard input. - [PROMPT_INJECTION]: The skill incorporates documentation in
persuasion-principles.mdandtesting-skills-with-subagents.mdthat teaches the use of psychological influence techniques (such as Authority and Scarcity) to override default model behavior and enforce strict adherence to documentation rules. These represent sophisticated prompt engineering patterns for controlling model output. - [EXTERNAL_DOWNLOADS]: The skill references external resources including Anthropic's official best practices and mentions the requirement for the Graphviz system utility, but it does not perform automated downloads or execute remote scripts.
Audit Metadata