prompt-enhance

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard prompt engineering utility. It processes text and provides a structured output based on principles of clarity and goal-setting.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes untrusted user input and local repository files to generate prompts that can subsequently be executed.\n
  • Ingestion points: Ingests user input from the argument-hint and content from files like AGENTS.md, CLAUDE.md, and README.md in the SKILL.md workflow.\n
  • Boundary markers: No specific boundary markers are defined to isolate untrusted content during processing.\n
  • Capability inventory: The skill allows for the immediate execution of the generated prompt ('run it now'), which could potentially trigger unintended actions if the input was malicious.\n
  • Sanitization: No input sanitization or validation is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 08:20 PM
Security Audit — agent-trust-hub — prompt-enhance