ai-optimization
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation and coding patterns for optimizing LLM context and cost. The included code snippets are best-practice templates for developers.
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for building systems that process untrusted conversation history and tool outputs. While the skill itself is safe, the described architectures represent a vulnerability surface if implemented without additional safeguards.
- Ingestion points: User messages and tool results processed in ConversationManager and pruneToolResults (SKILL.md).
- Boundary markers: None explicitly implemented in the provided code snippets.
- Capability inventory: The templates involve calls to LLM completion APIs (openai, anthropic).
- Sanitization: Recommends using json_schema for structured output, which improves resilience against prompt injection compared to unstructured prose.
Audit Metadata