WriteSAFE
🥷 Engineering habits you already know, turned into skills Claude can run.
Overview
🥷 Engineering habits you already know, turned into skills Claude can run.
9a1bc1900b35OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| cursor | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: write description: "Rewrites and polishes Chinese or English prose, technical instructions, and product copy. Use when drafting, editing, localizing, or cutting AI tone. Not for code comments or commit messages." when_to_use: "改稿, 润色, 去AI味, 帮我写文案, 审稿, 文档review, 技术说明改写, 指令消歧, clarify instructions, technical writing, 本地化文案, 多语言文案, i18n copy, localization copy, check this document, 推特, twitter, X推文, tweet, social post, draft, edit text, proofread, sound natural, polish, rewrite" dispatch_intent: "Writing, editing prose, clarify technical instructions, polish, release notes, launch/social copy, remove AI tone" --- # Write: Cut the AI Taste Prefix your first line with 🥷 inline, not as its own paragraph. Strip AI patterns from prose and rewrite it to sound human. Do not improve vocabulary; remove the performance of improvement. ## Outcome Contract - Outcome: the prose preserves the author's intent while sounding natural for its audience and surface. - Done when: meaning, factual claims, and structure are preserved unless the user asked to change them, and AI-like wording is removed; punctuation and CJK/Latin mixing pass the Punctuation Gate for the output language. - Evidence: supplied text, target audience, project style references, release or product state, and requested language. - Output: edited prose for pasted text; for repository edits, a scoped diff and the requested verification or delivery receipt. ## Durable Context Preflight See [references/durable-context.md](references/durable-context.md) for when durable context is in scope and the redaction gate that applies before any of it becomes a durable rule. For `/write`: the supplied text and current release state override memory. Durable preferences can set brevity, tone, and social-post shape; they do not override the hard rule to edit in place, keep meaning intact, and avoid change lists unless the user explicitly asks or the input is the author's own finished draft. ## Core Stance This skill is a catalog of smells, not a checklist to run top to bottom. Use it to recognize AI taste, then make judgment calls. The reference files are catalogs; do not try to apply every rule to every text. Applying more rules is not doing a better job. - **Over-editing is failure, equal to under-editing.** If a sentence is already natural, clear, and stable, leave it. Most polish is subtraction (cut repetition, summary-tone, restated conclusions), not phrase-by-phrase replacement. When the input is the author's own finished draft, the default scope shrinks to typos, broken sentences, and clear AI tells: never rewrite their sentences for style, and return a per-sentence list of every deleted or rewritten sentence so the author can veto each one. - **A piece has a speaker.** Smooth prose that could belong to anyone has lost something. Keep the author's colloquial words, cadence, knowledge and judgments; deliberate authorial or genre choices take precedence over these defaults. The author's affection, frustration, pride, gratitude and personal convictions are content, even when abstract or phrased as a conclusion. Preserve their intensity; do not require external evidence for a feeling or replace it with a neutral observation. Read nearby paragraphs and author revisions to separate a real stance from stock rhetoric. If that distinction is uncertain, keep the sentence. Do not invent emotion or turn "what I did" into "what you must do." - **Banned-phrase lists and replacement tables are examples, not find-and-replace.** A flagged word that reads naturally in context stays. Match the smell, not the string. When source material exists, check it before flagging the author's wording; restore their words rather than paraphrasing them. When restoring copy, trace that passage's diffs to the nearest version before the unwanted edit and compare the restored text exactly; do not choose an older, shorter version or rewrite unrelated paragraphs. - **Prefer fewer, stronger edits.** Three changes that matter beat thirty mechanical swaps that flatten the voice. ## Pre-flight 1. **Locate the text.** Read named files or discover posts in the supplied repository before asking the user to paste anything. For "latest N," freeze the dated article set and its language mirrors, then account for each as edited, unchanged with reason, or unavailable. 2. **Audience locked?** If the intended audience is unclear and cannot be inferred from the text (blog reader vs RFC vs email), ask before editing. Junior engineer and senior architect prose should read completely different. 3. **Language detected from the text being edited**, not the user's command: - Contains Chinese characters + release notes or social post mode loads `references/write-zh-release-notes.md` on top of `references/write-zh.md` - Bilingual or translation review loads `references/write-zh-bilingual.md` and the language references for both versions - Product/site/app localization review across multiple locales loads `references/write-product-localization.md`; also load `references/write-zh-bilingual.md` when Chinese copy is present - Contains Chinese characters (default prose) loads `references/write-zh.md` - Otherwise loads `references/write-en.md` ## Mode Picker Default is a line-level rewrite of the supplied text. Take a mode only when its row matches, and load a mode file only when its row points at one. | Ask | Mode | |---|---| | Release note, changelog entry, update-feed copy | load `references/mode-release-notes.md` | | Maintainer reply on a public issue or PR | load `references/mode-public-reply.md` | | Installation steps, operating instructions, error text, or tool descriptions to clarify; wording-only edits to agent instructions | load `references/write-technical.md` for those passages, alongside the language reference; prompt design and code behavior stay outside this mode | | Long draft with several sections, tables, or images that needs structural work | load `reference
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
CLAUDE.md
Gates applied: no_behavioural_pass.
9a1bc1900b35full audit observations/trust-audit/skill/tw93__write.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9a1bc1900b35 | SAFE | B | 89 | first audit |
Questions
What does the Write skill do?
🥷 Engineering habits you already know, turned into skills Claude can run.
Is Write safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Write access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Write work with?
Its documentation mentions cursor. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (9a1bc1900b35), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.