prompt-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Reference files references/evaluation-frameworks.md and references/system-prompts.md contain strings associated with prompt injection and jailbreaks (e.g., 'Ignore previous instructions', 'DAN'). These are documented within an adversarial test suite intended to help developers evaluate and improve prompt robustness, rather than acting as instructions for the agent to execute.\n- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it is designed to process external, untrusted data. Evidence chain:\n
  • Ingestion points: Untrusted data enters the context through templates like {{review}} in SKILL.md and {transcript} in references/structured-outputs.md.\n
  • Boundary markers: The skill provides explicit guidance on using delimiters such as <user_message> and XML tags to isolate data from instructions in references/system-prompts.md.\n
  • Capability inventory: Reference code performs data analysis and LLM calls (llm.complete) but lacks direct file-write or network-exfiltration capabilities.\n
  • Sanitization: Documentation covers validation using JSON schemas, Pydantic, and Zod to ensure structured data integrity in references/structured-outputs.md.\n- [SAFE]: All identified code snippets and external tool references are standard for prompt engineering and evaluation. The skill follows security best practices by teaching defensive prompt design and systematic testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — prompt-engineer