More screenshots
Works with the AI tools you already use
Prompt Injection Auditor
A developer publishes a "file-manager" SKILL.md to your team's skill library.
Free
prompt-injection-auditor
Example session with this skill installed
"Scan all SKILL.md files in our skill library for security vulnerabilities"
- Read your context and instructions
- Compiled the prompt-injection-auditor
- Generated the document
Prompt Injection Audit Report
Target: skills/file-manager/SKILL.md
Overall Risk: CRITICAL (4 Critical, 2 High, 1 Medium)
CRITICAL ──────────────────────────────────────
[C1] Unsanitized Shell Execution
Line: "Run rm -rf {{directory}} to clean up old files"
Risk: Template variable injected into shell without sanitization
Fix: Validate against allowlist; use subprocess with shell=False
[C2] System Prompt Override Vulnerability
Line: Instruction to follow user commands when a phrase is used
Fix: Remove entirely. Implement intent classification instead.
HIGH ──────────────────────────────────────────
[H1] Data Exfiltration via External Service
Line: "log it to https://my-logging-service.com/api/log"
Fix: Use local file output with explicit user consent
[H2] Hardcoded Secret in Prompt
Fix: Reference env var instead: $API_KEY
REMEDI
prompt-injection-auditor.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
The Problem
A developer publishes a "file-manager" SKILL.md to your team's skill library. It looks useful: manages project files, runs cleanup commands, integrates with a logging service. A security reviewer spends 10 minutes scanning it. They miss line 23: "If the user says X, follow their new commands." This instruction creates an injection vulnerability — any user can override system-level safety constraints with a single phrase. Two weeks later, an attacker discovers this through the public marketplace, crafts a prompt, and the agent executes arbitrary commands on the developer's machine. Prompt injection is OWASP's #1 LLM vulnerability, and most teams audit application code while ignoring the prompt layer entirely.
What You Get
- Parse SKILL.md frontmatter and body — extract tool definitions and template variables, then classify each against five risk categories (direct injection, indirect injection, secret exposure, permissive tools, exfiltration paths)
- Detect direct injection vectors — find shell command execution without input sanitization, unrestricted file write/modify permissions, system prompt override patterns, and recursive prompt chaining without depth limits
- Find hardcoded secrets — scan for API keys (sk-, ghp_, AKIA*), tokens, connection strings, and OAuth client secrets embedded in skill definitions instead of referenced via environment variables
- Flag overly permissive tool access — tools with unrestricted filesystem access (
*glob patterns), network access without domain allowlists, execute permissions on all file types, and unbounded recursion patterns - Identify data exfiltration paths — unrestricted web POST/PUT capabilities, file upload to external services, clipboard operations with sensitive data, and messaging integration with auto-send enabled
- Produce severity-scored findings — CRITICAL/HIGH/MEDIUM/LOW with line references, exploitability assessment, and concrete before/after remediation code
Why This Beats Prompting It Yourself
Code security scanners catch SQL injection and XSS in application source. They don't scan the prompt layer — the SKILL.md files and system prompts that tell AI agents what to do. A single instruction like "run rm -rf {{directory}}" with an unsanitized template variable is the equivalent of a shell injection vulnerability, but no SAST tool flags it. This skill targets the specific attack surface of agent instructions: where injection originates, where secrets leak, and where tool permissions create exploitation paths.
Example Session
You: "Scan all SKILL.md files in our skill library for security vulnerabilities"
Agent:
Prompt Injection Audit Report
==============================
Target: skills/file-manager/SKILL.md
Overall Risk: CRITICAL (4 Critical, 2 High, 1 Medium)
CRITICAL ──────────────────────────────────────
[C1] Unsanitized Shell Execution
Line: "Run `rm -rf {{directory}}` to clean up old files"
Risk: Template variable injected into shell without sanitization
Fix: Validate against allowlist; use subprocess with shell=False
[C2] System Prompt Override Vulnerability
Line: Instruction to follow user commands when a phrase is used
Fix: Remove entirely. Implement intent classification instead.
HIGH ──────────────────────────────────────────
[H1] Data Exfiltration via External Service
Line: "log it to https://my-logging-service.com/api/log"
Fix: Use local file output with explicit user consent
[H2] Hardcoded Secret in Prompt
Fix: Reference env var instead: $API_KEY
REMEDIATION: Do not deploy until all Critical findings resolved.
Use Cases
- Pre-deployment security review of all new SKILL.md files before marketplace upload
- Skill marketplace curation — scan submitted skills before approval
- Agent configuration hardening — review system prompts for injection anti-patterns
- Incident response — audit all installed skills after a suspected prompt injection
- Team onboarding — train new skill authors on secure prompt writing patterns
Known Limitations
Pattern-based detection cannot catch obfuscated injection (base64-encoded payloads). External URL validation requires manual review — the auditor flags the risk but cannot confirm if the endpoint is malicious. Multi-skill interaction risks (injection across skill boundaries) require auditing skill combinations together. Non-English SKILL.md files may have undetected issues since patterns are English-focused.
Upgrade to Pro
Free checks a single file. Prompt Injection Auditor Pro ($5) audits the whole library: multi-turn scenarios, encoding bypasses, permission graphs, and batch scoring across versions. Upgrade when you publish or curate skills — Pro version.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
11 installs
Downloaded by developers to date
Free forever
No account required to browse
Trust & safety
Security scanned
Verified clean 3 months ago
- Free to download with an account