prompt-improver
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data through the
$ARGUMENTSvariable to perform prompt optimization, creating a potential surface for indirect prompt injection attacks where malicious input could attempt to subvert the agent's logic. - Ingestion points: User input is processed via the
$ARGUMENTSplaceholder inSKILL.md. - Boundary markers: The input is delimited within markdown code blocks, which provides basic structural separation but does not prevent adversarial content from influencing the model's output.
- Capability inventory: The skill is restricted to text processing; it contains no scripts, file system access, network operations, or tool execution capabilities.
- Sanitization: No specific sanitization or filtering logic is present to validate the safety of the user-supplied prompt before processing.
- [NO_CODE]: The skill consists entirely of markdown instructions and does not include any scripts, binaries, or executable dependencies, significantly reducing the overall attack surface.
Audit Metadata