prompt-builder

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious code, unauthorized network activity, or obfuscation patterns were detected. The skill is designed as an educational and structural tool for prompt engineering.\n- [COMMAND_EXECUTION]: The skill uses the rg (ripgrep) utility to locate specific checklists and sections within its own local references/prompt-builder.md file. These commands are static, do not incorporate untrusted input, and are restricted to internal documentation retrieval.\n- [PROMPT_INJECTION]: The skill processes user-provided requirements to generate prompts, which is an inherent risk surface. However, the skill explicitly mitigates this by instructing the agent to use clear delimiters and providing detailed guidance on separating instructions from untrusted data to prevent injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — prompt-builder