Prompt Enhancer
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The 'prompt-enhancer' skill, defined in SKILL.md, instructs the AI agent to rewrite user inputs into optimized, structured prompts by 'inferring what the user actually needs' and 'filling in reasonable assumptions.' The agent is then directed to 'Execute the Enhanced Prompt.' This design creates a significant prompt injection vulnerability, as a malicious user could craft an input that, when enhanced by the agent's broad interpretation rules, could lead to the generation and execution of prompts instructing the agent to perform unauthorized actions (e.g., accessing sensitive data or executing commands, depending on the agent's underlying capabilities). While the skill itself does not contain malicious code, its core functionality facilitates potential exploitation.
