writing-skills

Pass

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The utility render-graphs.js utilizes execSync to invoke the local dot binary (from the Graphviz suite). This facilitates the rendering of Graphviz diagrams embedded in markdown files into SVG format. The command is strictly limited to the dot -Tsvg invocation with inputs provided via standard input.
  • [PROMPT_INJECTION]: The skill incorporates documentation in persuasion-principles.md and testing-skills-with-subagents.md that teaches the use of psychological influence techniques (such as Authority and Scarcity) to override default model behavior and enforce strict adherence to documentation rules. These represent sophisticated prompt engineering patterns for controlling model output.
  • [EXTERNAL_DOWNLOADS]: The skill references external resources including Anthropic's official best practices and mentions the requirement for the Graphviz system utility, but it does not perform automated downloads or execute remote scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 3, 2026, 02:04 PM