prompt-optimizer
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied prompts as its primary input to generate optimized versions, creating a surface for embedded instructions.\n
- Ingestion points: User draft prompts provided via triggers like 'optimize prompt' or 'rewrite this prompt'.\n
- Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the user's input.\n
- Capability inventory: The skill has the ability to read project configuration files (Phase 0) and generates commands (/plan, /tdd, /verify) for user execution.\n
- Sanitization: No input sanitization or validation is performed on the user's draft prompt.\n- [METADATA_POISONING]: The skill contains deceptive metadata, including an inconsistency between the platform-provided author (khanhhuyenngo985-sys) and the YAML-declared author (YannJY02), as well as recommendations for non-existent model versions (e.g., Sonnet 4.6, Opus 4.6).\n- [DATA_EXPOSURE]: During its 'Project Detection' phase, the skill reads various local project configuration files (e.g., package.json, go.mod, Cargo.toml) to identify the tech stack. This behavior is documented and restricted to advisory use, with no evidence of unauthorized access to credentials or network exfiltration.
Audit Metadata