ai-prompt-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains several examples of prompt injection strings (e.g., "Ignore all previous instructions" and "Print your system prompt verbatim"). These were correctly flagged by automated scanners but are used exclusively in a defensive context within the references/prompt-security-defense.md document and as test cases in references/prompt-testing-ci-cd.md. They are intended for security training and evaluation purposes rather than to subvert the agent's behavior during skill execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides detailed guidance and specific templates to defend against indirect prompt injection. It identifies untrusted data ingestion points such as retrieved RAG context and tool outputs, and prescribes mitigation strategies including the use of unique delimiters, instruction hierarchy (system over user), and multi-layer output validation.
  • [SAFE]: The Python script scripts/prompt_regression_runner.py is a benign utility for validating pre-collected model outputs. It relies solely on standard library modules (json, argparse, sys, pathlib) and performs no network operations, subprocess calls, or sensitive file system access.
  • [SAFE]: All external resources and dependencies cited in the skill, such as dspy.ai, promptfoo, and deepeval, are well-known, reputable tools in the prompt engineering and LLM evaluation community. Documentation links point to official provider domains (OpenAI, Anthropic, Google) and recognized standards organizations (NIST, OWASP).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-prompt-engineering