prompt-optimizer
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is explicitly defined as advisory-only. It contains clear instructions to the agent to avoid implementation actions such as writing code, creating files, or executing shell commands directly, focusing solely on generating optimized prompt text for user review.
- [DATA_EXPOSURE]: During 'Phase 0: Project Detection', the skill reads common project metadata files (e.g., package.json, go.mod, pyproject.toml, CLAUDE.md) to determine the tech stack. These are standard, non-sensitive development files. No access to credentials, environment variables, or private keys was detected.
- [COMMAND_EXECUTION]: Although the skill mentions various ecosystem commands like
/plan,/tdd, and/verify, these are utilized as components of the recommended prompt output rather than being invoked by the skill itself. - [PROMPT_INJECTION]: The skill processes user prompts and external project files (CLAUDE.md) which technically presents an indirect prompt injection surface. However, because the skill's primary purpose is to reformat this data into an advisory response reviewed by a human, and it lacks execution capabilities, the risk is negligible.
Audit Metadata