prompt-doctor

Pass

Audited by Gen Agent Trust Hub on Mar 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and associated metadata contain no evidence of malicious intent, obfuscation, or unauthorized operations. Its core functionality is focused on logical analysis and optimization of instructions.\n- [PROMPT_INJECTION]: While the skill processes external prompt data, it proactively mitigates injection risks. The 'Security Hardening' section establishes a clear instruction hierarchy and mandates the use of delimiters for user data. Mandatory Evidence Chain: (1) Ingestion points: Data is loaded via file-reading tools or user input as described in Workflow Step 1. (2) Boundary markers: The instructions explicitly require the use of delimiters (e.g., XML tags) to isolate user content. (3) Capability inventory: The skill has access to file-handling tools (Read, Write, Edit, Glob, Grep) but lacks network or system-level command access. (4) Sanitization: The prompt includes specific logic to guard against extraction, translation-based bypasses, and embedded instructions in external content.\n- [COMMAND_EXECUTION]: The skill uses file-system tools (Read, Write, Edit, Glob, Grep) exclusively for managing prompt files within the specified workspace. There are no patterns suggesting the execution of arbitrary shell commands, subprocess spawning, or modification of system configurations.\n- [DATA_EXFILTRATION]: No network-capable tools or suspicious connection patterns were identified. The skill does not attempt to access sensitive system files (e.g., SSH keys, credentials), and its file operations are restricted to prompt optimization tasks initiated by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 8, 2026, 01:50 PM