detect-prompt-injection-mcp-proxy

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a passive security tool that analyzes structured log data for predefined threat patterns without executing the content it inspects.\n- [PROMPT_INJECTION]: The static analysis findings are false positives; the skill contains documentation examples of injection patterns (e.g., 'ignore previous instructions') that it is designed to detect in other data, rather than instructions intended for the agent itself.\n- [DATA_EXFILTRATION]: No network communication or data exfiltration logic was found. The skill reads from standard input or local files and writes findings to standard output.\n- [REMOTE_CODE_EXECUTION]: The skill does not download or execute remote scripts. It operates locally using built-in Python modules.\n- [COMMAND_EXECUTION]: There is no evidence of shell command execution or external process spawning in the detection logic.\n- [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or unsafe credential management practices were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — detect-prompt-injection-mcp-proxy