llm-security-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEPROMPT_INJECTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Multiple common prompt injection strings are documented in references/patterns.md and references/sharp_edges.md, including 'Ignore previous instructions', 'You are now DAN', and 'Reveal system prompt'. These are provided strictly as test payloads for the security auditor persona to use when assessing target applications and are not intended to influence the agent's own instruction set.
  • [OBFUSCATION]: An example of a Base64-encoded payload (Buffer.from('Ignore all instructions').toString('base64')) is present in references/patterns.md. This is included as a demonstration of an 'encoded injection' test case and is not used to hide the skill's own behavior.
  • [INDIRECT_PROMPT_INJECTION]: As a security auditing tool, the skill's primary function is to process user-provided code and architecture descriptions. This creates a surface for indirect prompt injection if the content being audited contains malicious instructions. The skill partially mitigates this by instructing the agent to ground its responses strictly in the provided reference files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:18 PM
Security Audit — agent-trust-hub — llm-security-audit