octocode-prompt-optimizer

Pass

Audited by Gen Agent Trust Hub on Mar 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains no code or instructions that exhibit malicious intent. It is a well-structured tool designed for prompt engineering and instructional optimization.
  • [PROMPT_INJECTION]: The skill utilizes strong instructional markers like 'Triple Lock', 'CRITICAL', and 'FORBIDDEN'. These are used internally to enforce its optimization flow and preserve original logic, rather than attempting to override the agent's global safety protocols.
  • [PROMPT_INJECTION]: The skill ingests untrusted text data for optimization, which represents an indirect prompt injection surface. Ingestion points: Data is read from user-provided files in the 'READ' gate. Boundary markers: Internal XML-like tags (e.g., <read_gate>) are used, but external delimiters for user input are not specified. Capability inventory: Access is requested for file reading (localGetFileContent) and writing (ApplyPatch). Sanitization: A 'VALIDATE' gate is included to check output against quality standards and intent preservation.
  • [COMMAND_EXECUTION]: The skill includes instructions to use file-system tools for reading and patching text files. It features explicit restrictions forbidding the use of these tools for any purpose unrelated to prompt optimization.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 12, 2026, 07:32 AM