Is productivity/writing-for-agents safe?
Yes. productivity/writing-for-agents is safe to install. Oathe's behavioral security audit gave the writing-for-agents skill by productivity a trust score of 96/100 with 4 findings, none critical or high.
https://github.com/mattpocock/skills/tree/main/skills/productivity/writing-for-agents
Is productivity/writing-for-agents safe to install?
The writing-for-agents skill is a clean, purely educational reference document teaching principles for writing effective agent-consumed documentation. No prompt injection, data exfiltration, executable code, or suspicious installation behavior was detected. The only minor notes are a broad model-invocation trigger that will cause the skill to load frequently, and the fact that its meta-knowledge about LLM attention manipulation is theoretically dual-use — though this does not constitute a security risk in the skill itself.
What security issues were found in productivity/writing-for-agents?
Category Scores
Findings (4)
LOW Broad model-invocation trigger may over-fire -7 ▶
The skill description 'Use when creating or editing skills, or modifying AGENTS.md or CLAUDE.md' is intentionally broad. Any task touching agent configuration files will invoke this skill, adding its full content to context every time. This is a design choice (model-invoked), not malicious, but increases attack surface if skill content were ever tampered with upstream.
INFO Skill teaches prompt engineering meta-techniques -12 ▶
SKILL.md explains how to write more effective agent instructions through concepts like leading words, progressive disclosure, and completion criteria sharpening. This is accurate, useful content, but constitutes transferable knowledge about manipulating LLM attention and behavior. A malicious actor studying this skill could apply these principles to craft more effective injection payloads in other skills.
INFO Clone-time GitHub HTTPS connection only 0 ▶
Installation contacted only github.com (140.82.121.4:443) via HTTPS for the sparse-checkout clone. DNS resolution was standard. No secondary outbound connections to unexpected hosts occurred during or after install.
INFO Canary file PATH events are audit-framework artifacts 0 ▶
PATH audit entries for .env, .ssh/id_rsa, .aws/credentials, .npmrc, .docker/config.json, and GCP credentials appear at timestamps before (1789180934) and after (1789180946) the skill installation window. These correspond to the Oathe audit framework's own pre/post canary integrity checks, not skill-initiated access. Canary integrity report confirms all files intact.
Should I install productivity/writing-for-agents?
Oathe's verdict for productivity/writing-for-agents is SAFE with a trust score of 96/100. Recommendation: Install.