dx-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and profile developer workflows, team feedback, and project-specific pain points to generate automated scripts and configurations.
  • Ingestion points: Reads current developer workflows, team feedback, and project metadata (SKILL.md).
  • Boundary markers: The instructions do not define specific delimiters or warnings to ignore malicious instructions potentially embedded in the analyzed project data.
  • Capability inventory: The skill is instructed to modify project files including package.json scripts, Git hooks, .claude/commands/, and IDE configurations (SKILL.md).
  • Sanitization: There is no mention of sanitizing or validating the ingested project data before it is used to generate executable scripts or configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 08:36 PM
Security Audit — agent-trust-hub — dx-optimizer