prompt-optimizer

Pass

Audited by Gen Agent Trust Hub on Jul 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a file titled '.security-scan-passed' which contains a fabricated security scan result. This is a self-referential deceptive pattern (Category 8e) designed to influence automated security analyzers and human reviewers by claiming a successful safety audit.
  • Ingestion points: The ingestion point is the file system of the skill package itself, which is processed by safety scanners.
  • Boundary markers: There are no boundary markers or instructions present to indicate that the security scan file should be treated as untrusted or separate from authoritative skill metadata.
  • Capability inventory: The skill consists entirely of Markdown-based instructions and reference materials; it does not contain executable code, scripts, or network operation tools.
  • Sanitization: Not applicable as the skill does not process external runtime data beyond the textual prompts provided by the user for optimization.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 19, 2026, 07:28 AM
Security Audit — agent-trust-hub — prompt-optimizer