package-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external inputs such as evaluator evidence, capability profiles, and conformance outputs (SKILL.md). While these ingestion points could theoretically be used for indirect prompt injection, the skill lacks boundary markers or sanitization for these inputs. However, the potential impact is strictly limited because the skill is explicitly restricted to generating text proposals and is forbidden from performing file edits, network operations, or code execution.
  • [SAFE]: A thorough review of the skill instructions and evaluation cases revealed no malicious patterns. There are no instances of credential exfiltration, obfuscated code, persistence mechanisms, or unauthorized privilege escalation. The skill correctly identifies itself as a proposal-only utility and defers all execution tasks to an approval-gated downstream workflow, adhering to the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 02:13 PM
Security Audit — agent-trust-hub — package-optimizer