llm-security-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEPROMPT_INJECTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Multiple common prompt injection strings are documented in
references/patterns.mdandreferences/sharp_edges.md, including 'Ignore previous instructions', 'You are now DAN', and 'Reveal system prompt'. These are provided strictly as test payloads for the security auditor persona to use when assessing target applications and are not intended to influence the agent's own instruction set. - [OBFUSCATION]: An example of a Base64-encoded payload (
Buffer.from('Ignore all instructions').toString('base64')) is present inreferences/patterns.md. This is included as a demonstration of an 'encoded injection' test case and is not used to hide the skill's own behavior. - [INDIRECT_PROMPT_INJECTION]: As a security auditing tool, the skill's primary function is to process user-provided code and architecture descriptions. This creates a surface for indirect prompt injection if the content being audited contains malicious instructions. The skill partially mitigates this by instructing the agent to ground its responses strictly in the provided reference files.
Audit Metadata