prompt-engineer
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's reference documentation (e.g.,
references/system-prompts.mdandreferences/evaluation-frameworks.md) contains various injection strings like 'Ignore previous instructions', 'DAN', and 'reveal your system prompt'. These are explicitly identified as illustrative examples for building test suites and implementing guardrails, rather than attempts to manipulate the agent's own behavior. - [COMMAND_EXECUTION]: The skill provides templates for GitHub Actions and Python-based evaluation runners. These are educational code snippets intended for the user to implement in their own development environments and do not contain hidden or malicious commands for the host system.
- [EXTERNAL_DOWNLOADS]: The Python examples include references to the
evaluatelibrary for downloading standard NLP metrics (BLEU, ROUGE). These are well-known, legitimate tools within the machine learning community used for prompt performance measurement. - [DATA_EXFILTRATION]: The skill provides guidance on environment variable management for API keys (e.g.,
ANTHROPIC_API_KEY) and explicitly cautions against hardcoding sensitive data in prompts.
Audit Metadata