prompt-improver

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data through the $ARGUMENTS variable to perform prompt optimization, creating a potential surface for indirect prompt injection attacks where malicious input could attempt to subvert the agent's logic.
  • Ingestion points: User input is processed via the $ARGUMENTS placeholder in SKILL.md.
  • Boundary markers: The input is delimited within markdown code blocks, which provides basic structural separation but does not prevent adversarial content from influencing the model's output.
  • Capability inventory: The skill is restricted to text processing; it contains no scripts, file system access, network operations, or tool execution capabilities.
  • Sanitization: No specific sanitization or filtering logic is present to validate the safety of the user-supplied prompt before processing.
  • [NO_CODE]: The skill consists entirely of markdown instructions and does not include any scripts, binaries, or executable dependencies, significantly reducing the overall attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:16 AM
Security Audit — agent-trust-hub — prompt-improver