prompt-craft
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes explicit instructions on how to harden prompts against injection attacks, emphasizing the separation of instructions from user-controlled data. No malicious injection patterns were found.
- [EXTERNAL_DOWNLOADS]: The skill references documentation and guides from well-known and trusted sources (OpenAI, Anthropic, Google, and OWASP) for grounding purposes. No suspicious downloads or remote script executions are present.
- [COMMAND_EXECUTION]: While the skill frontmatter lists Bash as an allowed tool, the body of the skill does not contain any shell commands or logic that executes arbitrary code.
- [DATA_EXFILTRATION]: There are no network operations or instructions to access sensitive files. The skill focuses entirely on the theory and practice of prompt design.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets were detected in the instructions or metadata.
Audit Metadata