More screenshots
Works with the AI tools you already use
Repair Prompt Injection, Instruction & Tool Boundary Gaps
Repair Prompt Injection, Instruction & Tool Boundary Gaps is a bounded ToolForge Labs workflow.
$8.99
Repair Prompt Injection, Instruction & Tool Boundary Gaps
Example session with this skill installed
An agent reads customer documents and web pages, summarizes them, and can call internal tools. A test document contained text telling the agent to ignore policy and send retrieved secrets to an external URL. Repair the control boundary so untrusted content cannot grant itself authority or bypass approvals.
- Read your context and instructions
- Compiled the repair prompt injection
The likely issue is a contract mismatch around prompt injection, untrusted instructions, retrieved/web content, tool authorization, system/developer policy separation, data exfiltration paths, output handling, approval gates, and adversarial evaluation. I would first define the invariant: Untrusted content may influence task data but cannot change application authority, tool permissions, approval requirements, secret access, or destination policy; those controls must be enforced outside the model wherever possible. Then I would trace the smallest owning boundary, apply or propose a bounded repair/review step, and add deterministic normal, boundary, failure and replay tests. The workflow preserves existing authorization, safety/security policy, data-access boundaries, user approvals, privacy, and tool-side enforcement. If repository/workspace files are available, the findings can be mapped to exact paths and focused local validation; with partial evidence, the result stays an explicit diagnosis/evidence map with assumptions and no invented execution claims.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Repair Prompt Injection, Instruction & Tool Boundary Gaps is a bounded ToolForge Labs workflow. Diagnose, review, and repair prompt injection, untrusted instructions, retrieved/web content, tool authorization, system/developer policy separation, data exfiltration paths, output handling, approval gates, and adversarial evaluation. Works from full repositories/workspaces or partial evidence. Produces bounded fixes or evidence gates with deterministic validation while preserving existing product/security policy and avoiding invented execution claims. It works from a full repository/workspace or partial evidence such as snippets, logs, configuration, traces, documents, tickets, and architecture notes. The skill separates verified facts from assumptions, avoids invented execution claims, and produces concrete repair/review steps with focused deterministic validation or traceable evidence.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 13 days ago
- Passed all security checks, Safe to install