prompt-factory
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves collecting user requirements through an interactive flow and interpolating that data into complex prompt templates. This ingestion surface is well-managed and follows safe design patterns.
- Ingestion points: User-supplied requirements gathered through the 5-to-7 question flow defined in
SKILL.md. - Boundary markers: Output is structured using formal XML tags (e.g.,
<mega_prompt>,<role>,<mission>) and clear markdown headers as defined inscripts/generate_prompt.py. - Capability inventory: The skill utilizes local Python scripts (
scripts/batch_generator.py,scripts/generate_prompt.py) for processing text and writing generated prompts to the local filesystem. - Sanitization: While no regex-based sanitization is performed on user strings,
SKILL.mdcontains a prominent 'CRITICAL CONSTRAINTS' section that explicitly instructs the agent to treat the output as a prompt document only and strictly forbids implementing or executing the instructions contained within the generated content. - [SAFE]: The skill includes several Python scripts (
validator.py,optimizer.py,batch_generator.py) for automation and quality assurance. These scripts are implemented using the Python standard library and perform text analysis via regex without constructing shell commands or utilizing dynamic execution sinks likeeval()orexec(). Path operations are handled securely usingpathlibwith no evidence of path traversal vulnerabilities.
Audit Metadata