enhance-prompts

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the node -e command to execute a local JavaScript analyzer script (lib/enhance/prompt-analyzer.js). This is a standard execution pattern for project-based developer tools.
  • [DYNAMIC_EXECUTION]: The core logic is implemented in a local module that is dynamically loaded via require() and executed within a Node.js process. This allows the skill to perform complex AST-based validation of prompt files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze prompts from the filesystem, which are inherently untrusted data sources. While these prompts could contain adversarial instructions, the skill's narrow scope of generating reports and applying structured 'auto-fixes' limits the potential impact.
  • Ingestion points: The skill reads prompt files from the specified targetPath or the current directory.
  • Boundary markers: The skill does not explicitly define delimiters for untrusted content in its documentation, though the analysis is handled by an external script.
  • Capability inventory: The skill has the capability to read files, execute Node.js code, and modify files if the --fix flag is enabled.
  • Sanitization: Sanitization and validation logic are expected to be contained within the prompt-analyzer.js utility rather than the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:14 AM
Security Audit — agent-trust-hub — enhance-prompts