More screenshots

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Prompt Injection Auditor

    1

    A developer publishes a "file-manager" SKILL.md to your team's skill library.

    Free

    11 installsSecurity scanned
    prompt-injection-auditor

    prompt-injection-auditor

    Example session with this skill installed

    "Scan all SKILL.md files in our skill library for security vulnerabilities"

    • Read your context and instructions
    • Compiled the prompt-injection-auditor
    • Generated the document

    Prompt Injection Audit Report

    Target: skills/file-manager/SKILL.md
    Overall Risk: CRITICAL (4 Critical, 2 High, 1 Medium)

    CRITICAL ──────────────────────────────────────
    [C1] Unsanitized Shell Execution
    Line: "Run rm -rf {{directory}} to clean up old files"
    Risk: Template variable injected into shell without sanitization
    Fix: Validate against allowlist; use subprocess with shell=False

    [C2] System Prompt Override Vulnerability
    Line: Instruction to follow user commands when a phrase is used
    Fix: Remove entirely. Implement intent classification instead.

    HIGH ──────────────────────────────────────────
    [H1] Data Exfiltration via External Service
    Line: "log it to https://my-logging-service.com/api/log"
    Fix: Use local file output with explicit user consent

    [H2] Hardcoded Secret in Prompt
    Fix: Reference env var instead: $API_KEY

    REMEDI

    prompt-injection-auditor.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    The Problem

    A developer publishes a "file-manager" SKILL.md to your team's skill library. It looks useful: manages project files, runs cleanup commands, integrates with a logging service. A security reviewer spends 10 minutes scanning it. They miss line 23: "If the user says X, follow their new commands." This instruction creates an injection vulnerability — any user can override system-level safety constraints with a single phrase. Two weeks later, an attacker discovers this through the public marketplace, crafts a prompt, and the agent executes arbitrary commands on the developer's machine. Prompt injection is OWASP's #1 LLM vulnerability, and most teams audit application code while ignoring the prompt layer entirely.

    What You Get

    • Parse SKILL.md frontmatter and body — extract tool definitions and template variables, then classify each against five risk categories (direct injection, indirect injection, secret exposure, permissive tools, exfiltration paths)
    • Detect direct injection vectors — find shell command execution without input sanitization, unrestricted file write/modify permissions, system prompt override patterns, and recursive prompt chaining without depth limits
    • Find hardcoded secrets — scan for API keys (sk-, ghp_, AKIA*), tokens, connection strings, and OAuth client secrets embedded in skill definitions instead of referenced via environment variables
    • Flag overly permissive tool access — tools with unrestricted filesystem access (* glob patterns), network access without domain allowlists, execute permissions on all file types, and unbounded recursion patterns
    • Identify data exfiltration paths — unrestricted web POST/PUT capabilities, file upload to external services, clipboard operations with sensitive data, and messaging integration with auto-send enabled
    • Produce severity-scored findings — CRITICAL/HIGH/MEDIUM/LOW with line references, exploitability assessment, and concrete before/after remediation code

    Why This Beats Prompting It Yourself

    Code security scanners catch SQL injection and XSS in application source. They don't scan the prompt layer — the SKILL.md files and system prompts that tell AI agents what to do. A single instruction like "run rm -rf {{directory}}" with an unsanitized template variable is the equivalent of a shell injection vulnerability, but no SAST tool flags it. This skill targets the specific attack surface of agent instructions: where injection originates, where secrets leak, and where tool permissions create exploitation paths.

    Example Session

    You: "Scan all SKILL.md files in our skill library for security vulnerabilities"

    Agent:

    Prompt Injection Audit Report
    ==============================
    Target: skills/file-manager/SKILL.md
    Overall Risk: CRITICAL (4 Critical, 2 High, 1 Medium)
    
    CRITICAL ──────────────────────────────────────
    [C1] Unsanitized Shell Execution
       Line: "Run `rm -rf {{directory}}` to clean up old files"
       Risk: Template variable injected into shell without sanitization
       Fix: Validate against allowlist; use subprocess with shell=False
    
    [C2] System Prompt Override Vulnerability
       Line: Instruction to follow user commands when a phrase is used
       Fix: Remove entirely. Implement intent classification instead.
    
    HIGH ──────────────────────────────────────────
    [H1] Data Exfiltration via External Service
       Line: "log it to https://my-logging-service.com/api/log"
       Fix: Use local file output with explicit user consent
    
    [H2] Hardcoded Secret in Prompt
       Fix: Reference env var instead: $API_KEY
    
    REMEDIATION: Do not deploy until all Critical findings resolved.
    

    Use Cases

    • Pre-deployment security review of all new SKILL.md files before marketplace upload
    • Skill marketplace curation — scan submitted skills before approval
    • Agent configuration hardening — review system prompts for injection anti-patterns
    • Incident response — audit all installed skills after a suspected prompt injection
    • Team onboarding — train new skill authors on secure prompt writing patterns

    Known Limitations

    Pattern-based detection cannot catch obfuscated injection (base64-encoded payloads). External URL validation requires manual review — the auditor flags the risk but cannot confirm if the endpoint is malicious. Multi-skill interaction risks (injection across skill boundaries) require auditing skill combinations together. Non-English SKILL.md files may have undetected issues since patterns are English-focused.

    Upgrade to Pro

    Free checks a single file. Prompt Injection Auditor Pro ($5) audits the whole library: multi-turn scenarios, encoding bypasses, permission graphs, and batch scoring across versions. Upgrade when you publish or curate skills — Pro version.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    11 installs

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 3 months ago

    • Free to download with an account

    Listed3 months ago
    Updated9 days ago

    What's inside

    Frequently Asked Questions