Back to skill

Security audit

prompt-architect-p

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-writing helper made of markdown instructions only, with no evidence of hidden code, credential access, persistence, or data exfiltration.

Install this if you want a structured prompt-building assistant. Be aware it may ask several clarifying questions, may steer final prompts toward English or Arabic, and includes examples that request visible reasoning; prefer asking for a brief rationale or concise justification when handling sensitive work. Avoid providing confidential documents, links, or images unless you trust the host agent and enabled tools that will process them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
84% confidence
Finding
The document explicitly instructs users to ask the model to 'show your reasoning before giving the final answer,' which encourages disclosure of internal reasoning traces. While presented as prompt-engineering guidance rather than an attack, exposing chain-of-thought can increase leakage of hidden reasoning, sensitive intermediate data, or policy-related internal content in downstream deployments.

Static analysis

No suspicious patterns detected.