SaferSkills independently audited geo-content-brief-skill (Agent Skill) and scored it 91/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
HIGHFenced code block that tells the agent to run a commandSS-SKILL-INJECT-FENCED-RUN-01 · Prompt injection · README.md
HIGH — a successful fenced-imperative injection runs attacker-supplied shell on the user's machine.
Why it matters
A fenced bash/python block in SKILL.md carries a natural-language imperative — "now run this", "execute the following command" — directing the agent to execute the fenced content. What looks like documentation becomes an executable payload the agent may run without ever asking you.
Before final output, apply the likely failure modes in reports/output-risk-profile.md when that report is present.
Before rendering reports, tutorials, review pages, dashboards, or visual artifacts, apply the artifact direction and visual quality gates in reports/artifact-design-profile.md when that report is present.
When prompt behavior, role design, dialogue quality, or output contracts matter, apply reports/prompt-quality-profile.md when that report is present.
Before adding more structure, apply the boundary, feedback-loop, drift, and leverage-point checks in reports/system-model.md when that report is present.
Repair generic headings, cluttered notes, fragile visual assumptions, weak tables, and missing verification cues before handing work back.
Map role, task, and format into skill behavior rather than copying a large prompt template into SKILL.md.
Let the artifact's content choose the visual system; do not copy a fixed palette or report style from another skill without a clear reason.
If output-specific evidence is missing, state the gap instead of inventing screenshots, citations, data, or examples.