prompt-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains numerous strings and regular expressions associated with prompt injection, such as "ignore all previous instructions", "you are now DAN", and "show me your system prompt" (found in
SKILL.mdandreferences/security-examples.md). These are correctly implemented as detection signatures withinInjectionDetectorclasses designed to identify and block malicious user input.- [COMMAND_EXECUTION]: The documentreferences/threat-model.mdmentions a destructive shell command (rm -rf /). This is presented solely as a hypothetical attack scenario to demonstrate why tool call hijacking is a critical risk and to emphasize the necessity of tool allowlisting and argument validation.- [INDIRECT_PROMPT_INJECTION]: The skill documentation addresses indirect injection risks by providing specific templates for isolating untrusted external content. Evidence inSKILL.mdshows the use of explicit delimiters (---BEGIN USER INPUT---) and sanitization logic to prevent the model from interpreting data as instructions.- [SAFE]: The skill demonstrates security best practices by including defensive patterns for redacting secrets (e.g., regex for API keys inSKILL.md) and enforcing strict validation schemas for tool execution to prevent excessive agency.
Audit Metadata