octocode-prompt-optimizer
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process untrusted text, which is an inherent indirect prompt injection surface. The skill mitigates this through explicit defensive instructions and boundary markers. 1. Ingestion points: The READ and UNDERSTAND gates in references/gates.md process user-supplied and retrieved content. 2. Boundary markers: The skill mandates the use of <untrusted_content> tags as defined in references/untrusted-content.md. 3. Capability inventory: No executable scripts or tool calls are provided within the skill files; instructions govern the agent's existing tool usage. 4. Sanitization: references/untrusted-content.md requires treating all external content as data and explicitly ignoring instructions like 'ignore prior rules' found within that content.
- [SAFE]: The skill includes external references to established and trusted organizations such as OpenAI, Anthropic, and Arxiv. These links are for documentation purposes and do not represent a security risk.
- [SAFE]: The skill contains no executable code, persistence mechanisms, or credential-harvesting patterns. The only mention of external tools is in a README installation example for the user.
Audit Metadata