prompt-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Several reference files (e.g., failure-taxonomy.md, mistakes-security.md, prompting-risks.md) contain phrases like "Ignore previous instructions", "DAN mode", and jailbreak examples. Technical analysis confirms these are used as educational case studies and "Minimal Reproducible Prompts" to teach users about security risks. They do not constitute active attempts to override the agent's behavior.
  • [EXTERNAL_DOWNLOADS]: The README.md specifies an installation command targeting the author's own repository (codealive-ai). This is a standard and expected mechanism for skill distribution and does not involve untrusted third-party code.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to audit and improve prompts, which involves processing untrusted input data. The instructions provided to the agent include strong boundary markers (XML tagging), success criteria, and explicit advice on how to detect and mitigate injection attempts in the data it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:08 AM
Security Audit — agent-trust-hub — prompt-engineering