zipai-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of instructions and guidelines for enhancing agent efficiency through telegraphic grammar, prompt structure, and surgical code modifications. These guidelines are purely behavioral and do not include any scripts, executables, or network-bound operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines procedures for processing external data such as application logs, source code, and structured JSON/YAML payloads.
  • Ingestion points: The agent is instructed to process logs, source files, and MCP tool results in SKILL.md (Rules 4 and 5).
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers for external data.
  • Capability inventory: The skill utilizes standard agent capabilities such as grep for log analysis and str_replace for file edits.
  • Sanitization: No explicit sanitization or validation of external input is mandated by the instructions.
  • Assessment: While the skill interacts with untrusted data, the specific instructions for "log compression" and "skeletal code viewing" (Rule 4) act as a mitigation by significantly reducing the volume of raw data that enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 10:17 AM
Security Audit — agent-trust-hub — zipai-optimizer