prompt-optimizer

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill reads local project manifest files (such as package.json, go.mod, pyproject.toml, Cargo.toml, etc.) and the CLAUDE.md file to identify the project's tech stack. This information is used exclusively to generate relevant advice and optimize the user's prompt; no evidence of data exfiltration was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user-provided prompts and local project metadata. However, the skill includes explicit instructions to remain in an "Advisory only" mode, specifically prohibiting the creation of files, execution of commands, or implementation of code. This strict constraint effectively mitigates risks associated with indirect prompt injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 04:01 AM
Security Audit — agent-trust-hub — prompt-optimizer