A

Is writing-skills safe?

obra/superpowers · scanned Oct 4, 2026

What it says it does

Use when creating new skills, editing existing skills, or verifying skills work before deployment

A
Score 98/100

No significant risks found by the automated scan.

Low · 1
Source
Repository
obra/superpowers/skills/writing-skills
Commit
8ca22dba9a94
Scanned
Oct 4, 2026
Files checked
7
Stars
295k
License
MIT
Last push
Sep 27, 2026
What it can reach
External domains mentioned anywhere in the skill's files.
agentskills.iocode.claude.commintcdn.complatform.claude.com
Findings (1)
Pattern matches are leads, not proof. A finding in documentation is often harmless; one in a script deserves a closer look.
LowRuns shell commandsCode execution

Many legitimate skills run commands. Check that the commands match what the skill says it does.

skills/writing-skills/render-graphs.js:18

import { execFileSync } from 'child_process';
Files scanned (7)
  • skills/writing-skills/anthropic-best-practices.md (45.1 KB)
  • skills/writing-skills/examples/CLAUDE_MD_TESTING.md (5.3 KB)
  • skills/writing-skills/graphviz-conventions.dot (5.8 KB)
  • skills/writing-skills/persuasion-principles.md (5.8 KB)
  • skills/writing-skills/render-graphs.js (4.9 KB)
  • skills/writing-skills/SKILL.md (26.0 KB)
  • skills/writing-skills/testing-skills-with-subagents.md (12.3 KB)
Add the badge to your README
Shows the current grade and links back to this report. It updates when the skill is rescanned.
SkillsVetted grade A
[![SkillsVetted grade](https://skillsvetted.com/badge/obra/writing-skills.svg)](https://skillsvetted.com/skills/obra/writing-skills)
Rescan
Pull the latest commit from GitHub and update this listing.
Want a human to check it?

A full review covers what pattern matching can't: intent, logic and behavior in a sandbox.

Request full review