mj-prompt

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a 'Forbidden Words' section (Section IX) that provides specific replacement terms designed to bypass safety filters in the target image generation system (Midjourney). It instructs the agent to use euphemisms for restricted concepts such as 'blood', 'violence', and 'horror'.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions define an automated workflow (Section XI) where user-provided input and agent-generated scores trigger file creation and modification on the local system. The lack of explicit boundary markers or input sanitization creates a surface for indirect prompt injection.
  • Ingestion points: User-provided 'creation requirements' or 'demands' used to generate prompts and trigger the scoring/extraction logic in Section XI.
  • Boundary markers: Absent. The skill does not employ delimiters or specific instructions to treat user data as non-executable text or strictly data-only.
  • Capability inventory: File creation and modification operations, including writing to 'reverse-report.md', 'knowledge-base/prompt-patterns.json', and 'iteration-report.json'.
  • Sanitization: Absent. There is no evidence of validation or escaping logic for user input before it is incorporated into the generated reports or structured JSON data files.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 03:47 PM
Security Audit — agent-trust-hub — mj-prompt