prompt-optimizer
Pass
Audited by Gen Agent Trust Hub on Jul 19, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes a file titled '.security-scan-passed' which contains a fabricated security scan result. This is a self-referential deceptive pattern (Category 8e) designed to influence automated security analyzers and human reviewers by claiming a successful safety audit.
- Ingestion points: The ingestion point is the file system of the skill package itself, which is processed by safety scanners.
- Boundary markers: There are no boundary markers or instructions present to indicate that the security scan file should be treated as untrusted or separate from authoritative skill metadata.
- Capability inventory: The skill consists entirely of Markdown-based instructions and reference materials; it does not contain executable code, scripts, or network operation tools.
- Sanitization: Not applicable as the skill does not process external runtime data beyond the textual prompts provided by the user for optimization.
Audit Metadata