prompt-craft

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes explicit instructions on how to harden prompts against injection attacks, emphasizing the separation of instructions from user-controlled data. No malicious injection patterns were found.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation and guides from well-known and trusted sources (OpenAI, Anthropic, Google, and OWASP) for grounding purposes. No suspicious downloads or remote script executions are present.
  • [COMMAND_EXECUTION]: While the skill frontmatter lists Bash as an allowed tool, the body of the skill does not contain any shell commands or logic that executes arbitrary code.
  • [DATA_EXFILTRATION]: There are no network operations or instructions to access sensitive files. The skill focuses entirely on the theory and practice of prompt design.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets were detected in the instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 04:34 AM
Security Audit — agent-trust-hub — prompt-craft