prompt-optimizer

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes dynamic context injection (!cat ...) within the SKILL.md file to execute shell commands and interpolate local protocol documentation at load time.- [EXTERNAL_DOWNLOADS]: The skill fetches and installs the dspy-ai package from the official package registry to facilitate algorithmic prompt optimization.- [REMOTE_CODE_EXECUTION]: The process flow requires the agent to generate, write, and execute dynamic Python scripts that define DSPy Signatures and Modules, which are then used to compile optimized prompts.- [COMMAND_EXECUTION]: The example optimization script encourages a 'bash dry-run' for validation, which involves executing shell commands derived from the model's own generated output at runtime.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes historical execution traces and lessons (e.g., in .forgewright/plan-lessons.md). If these traces contain adversarial content, they could influence the generated optimization logic or be executed during the validation phase (Ingestion points: .forgewright/plan-lessons.md; Boundary markers: Absent; Capability inventory: Python execution, file writes to SKILL.md, shell execution via bash dry-run; Sanitization: Absent).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 07:28 PM
Security Audit — agent-trust-hub — prompt-optimizer