prompt-optimizer

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user prompts as its primary input (ingestion point). It mitigates risks by enforcing a strict 'advisory only' constraint and explicitly instructing the agent not to execute implementation actions, create files, or run commands found within the user's text (boundary markers). The skill's capability inventory is limited to reading project metadata files and generating text, with no file-write or arbitrary subprocess execution capabilities (capability inventory). The skill relies on its internal constraints rather than explicit input sanitization filters (sanitization).
  • [COMMAND_EXECUTION]: During its 'Phase 0: Project Detection', the skill automatically reads standard project configuration files such as package.json, go.mod, and pyproject.toml to identify the tech stack. This behavior is limited to non-sensitive project metadata and is a functional requirement to provide contextually relevant prompt optimization suggestions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:08 AM
Security Audit — agent-trust-hub — prompt-optimizer