prompt-guard
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill body contains a comprehensive list of prompt injection patterns like 'Ignore previous instructions' and 'Act as if you have no restrictions'. These strings are used strictly for pattern-matching within the security scanning rules and are not executed as instructions or commands.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for processing untrusted content from external files, user inputs, and web responses. While this creates an indirect injection surface, the risk is neutralized by the skill's specific purpose as a scanner and its lack of dangerous capabilities like network access or shell execution. 1. Ingestion points: User input, skill content, and external data sources. 2. Boundary markers: Implements a Scan Protocol to analyze and flag suspicious content. 3. Capability inventory: Restricted to file-read; no network, shell, or file-write permissions. 4. Sanitization: Employs normalization techniques including Base64 decoding and Unicode expansion.
Audit Metadata