promptor

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or deceptive behaviors were detected in the skill files. The instructions are transparent and aligned with the stated purpose of prompt engineering.
  • [DATA_EXPOSURE]: No hardcoded credentials, API keys, or attempts to access sensitive system files (e.g., SSH keys, environment variables) were identified.
  • [REMOTE_CODE_EXECUTION]: The skill does not perform runtime remote code execution or download external scripts. Installation via Git clone from the author's repository is a standard, user-initiated setup procedure.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data via {{USER_REQUEST}} and {{INPUT_CONTEXT}}. However, it includes a dedicated 'Input sanitization' constraint that instructs the agent to check for injection patterns and flag them before processing, mitigating the risk of indirect prompt injection.
  • [COMMAND_EXECUTION]: There are no high-risk shell commands or privilege escalation attempts. The optimization 'hacks' described (e.g., disabling unused tools, limiting sub-agents) are security-positive configurations that promote the principle of least privilege.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 11:30 AM
Security Audit — agent-trust-hub — promptor