prompt-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: CRITICALPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The reference documentation (references/system-prompts.md) includes various injection and jailbreak strings as examples for building test suites. These are pedagogical examples meant to improve prompt robustness and are not active instructions targeting the agent.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external text data, which is a potential vector for injection. Ingestion points: Variable interpolation in prompt templates. Boundary markers: Recommends XML tagging and clear instruction/data separation. Capability inventory: Snippets perform text analysis using standard libraries like scikit-learn. Sanitization: Guidance includes instruction priority rules and treating user messages as content rather than commands.
- [EXTERNAL_DOWNLOADS]: The skill links to its own documentation hosted on GitHub Pages (jeffallan.github.io). Automated scanners have flagged these URLs, but the detections appear to be false positives triggered by the security research content (adversarial prompt examples) hosted within the skill's reference files.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata