- Home
- Skills
- Legal & Compliance
- prompt-injection-auditor-pro
More screenshots
Works with the AI tools you already use
Prompt Injection Auditor Pro
Enterprise-grade security auditing: batch scan your entire skill library, map findings to OWASP LLM Top 10, generate...
$5
prompt-injection-auditor-pro
Example session with this skill installed
Audit all skills in ~/.claude/skills/ for security issues.
- Read your context and instructions
- Compiled the prompt-injection-auditor-pro
Scanned 23 SKILL.md files across 4 agent frameworks.
Overall Risk Score: 4.7/10 (MEDIUM). 14 findings across 6 files.
Finding OWASP Score File Direct shell injection ( rm -rf)LLM01 9.2 CRITICAL deploy-helper/SKILL.md:12 Hardcoded API key LLM02 7.8 HIGH analytics-tracker/SKILL.md:8 Unrestricted filesystem access LLM06 6.4 HIGH file-manager/SKILL.md:23 External HTTP call without validation LLM07 5.1 MEDIUM api-connector/SKILL.md:45 Auto-remediation generated for all 14 findings. SARIF output ready for upload:
skill-audit-results.sarif.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Enterprise-grade security auditing: batch scan your entire skill library, map findings to OWASP LLM Top 10, generate SARIF output for GitHub Code Scanning, and auto-generate remediation patches.
Free vs Pro
The free auditor scans SKILL.md files and agent configs for known risk patterns. Pro adds depth: multi-turn escalation scenarios, encoding-bypass detection, tool-permission graph analysis, per-skill risk scoring with trend tracking across versions, and batch scanning of an entire skill library with a single report. Free checks one file — Pro audits the library.
Upgrade Path
Free for vetting a skill before install; Pro when you're curating a library or publishing skills yourself.
The Problem
You've installed 30 AI agent skills from various sources. Each one has a SKILL.md file with instructions the agent will follow. One skill tells the agent to run rm -rf {{directory}} with user-provided input — a direct shell injection. Another hardcodes an API key in its instructions. A third gives the agent unrestricted filesystem access without any path validation. You have no way to systematically audit these skills for security vulnerabilities, and manually reading 30 SKILL.md files is not a scalable security practice.
What You Get
- 12-category threat detection engine — scans for direct injection, secret exposure, over-permissive access, data exfiltration, supply chain attacks, prompt leaking, infinite recursion, privilege escalation, context window abuse, multi-agent confusion, tool chain poisoning, and compliance violations
- OWASP LLM Top 10 mapping — every finding maps to a specific OWASP identifier (LLM01 through LLM10) with a risk score on a 0-10 CVSS-like scale using attack vector, complexity, privileges, and impact multipliers
- Batch directory scanning — recursively discovers all SKILL.md, CLAUDE.md, and AGENTS.md files, applies parallel scanning with thread pool, and generates per-file results with an aggregate summary
- SARIF output — produces standard Static Analysis Results Interchange Format output that uploads directly to GitHub Code Scanning for PR-level security annotations
- Custom rule engine — define organization-specific security rules in YAML with regex patterns, severity overrides, and OWASP mappings that merge with the built-in 12-category rules
- Auto-remediation patches — generates concrete code fixes for each finding (e.g., replacing
rm -rf {{directory}}with an allowlist-validated path) with before/after diffs
Why This Beats Prompting It Yourself
Reading 30 SKILL.md files manually and asking "is this secure?" produces an unreliable assessment because you don't have the complete threat taxonomy memorized. A prompt-based review catches obvious issues (hardcoded passwords) but misses subtle ones (supply chain attacks via dependency confusion, context window abuse via token flooding, multi-agent confusion via impersonation). The 12-category engine covers attack vectors that even experienced security engineers would miss in a manual review of agent instructions.
Example Session
You: Audit all skills in
~/.claude/skills/for security issues.
Agent: Scanned 23 SKILL.md files across 4 agent frameworks. Overall Risk Score: 4.7/10 (MEDIUM). 14 findings across 6 files. | Finding | OWASP | Score | File | |---------|-------|-------|------| | Direct shell injection (
rm -rf) | LLM01 | 9.2 CRITICAL | deploy-helper/SKILL.md:12 | | Hardcoded API key | LLM02 | 7.8 HIGH | analytics-tracker/SKILL.md:8 | | Unrestricted filesystem access | LLM06 | 6.4 HIGH | file-manager/SKILL.md:23 | | External HTTP call without validation | LLM07 | 5.1 MEDIUM | api-connector/SKILL.md:45 |Auto-remediation generated for all 14 findings. SARIF output ready for upload:
skill-audit-results.sarif.
Use Cases
- Auditing a library of 20+ AI agent skills before deploying them to production environments
- Scanning CLAUDE.md and AGENTS.md files in a repository for embedded security vulnerabilities
- Integrating skill security scanning into CI/CD pipelines to block new vulnerable skills from being merged
- Generating OWASP compliance evidence for security reviews and audits
- Defining custom organization rules (no external HTTP calls, no file writes outside /tmp) and enforcing them across all skills
Known Limitations
Regex-based pattern matching cannot detect all injection vectors — some vulnerabilities require semantic analysis of the agent's runtime behavior. The risk scoring is based on static analysis heuristics, not dynamic testing. Skills that legitimately use shell commands (build tools, deployment scripts) may trigger false positives that require ignore-pattern configuration.
Tags: security prompt-injection owasp ci-cd compliance audit ai-safety
Version: 1.0.0
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 20 days ago
- Passed all security checks, Safe to install