prompt-optimizer

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's core functionality is providing instructional guidance for prompt engineering. It does not execute scripts, download external content, or perform any automated system actions.
  • [DATA_EXPOSURE]: No sensitive file paths, hardcoded credentials, or environment variable accesses were detected. The skill operates only on the text provided by the user in the conversational context.
  • [PROMPT_INJECTION]: The instructions do not contain any patterns typical of prompt injection, such as attempts to bypass safety filters, disregard previous instructions, or extract system prompts. Phrases like 'IMPORTANT' are used correctly within the context of emphasizing best practices for prompt analysis.
  • [REMOTE_CODE_EXECUTION]: There are no remote code execution patterns, subprocess calls, or dynamic code generation techniques present in the skill's files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process untrusted user inputs (prompts to be optimized), it lacks the dangerous capabilities (network access, file writes, command execution) necessary to exploit such an injection. The output is limited to text suggestions, making the risk negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 12:15 PM
Security Audit — agent-trust-hub — prompt-optimizer