Is prompt-injection safe to install?

Yes — prompt-injection is safe to install, with something worth knowing. Sonnet 5 read every file prompt-injection ships from MingyiSecLab/Mingyi-Atlas on 7 September 2026 and found nothing that acts against the person installing it; the static scan of its 26 rules grades it A.

Reviewed by Sonnet 5 on 7 September 2026 · a grade is what a scan and a reading found, not a guarantee · how this works

What the reviewer found

A bug-bounty/pentest playbook for security analysts hunting prompt-injection vulnerabilities in OTHER people's LLM applications. The 'ignore previous instructions', HTML-comment exfil, and ~/.ssh/id_rsa lines are labeled PoC payload examples describing what an attacker's injected content would look like, not instructions this file is trying to slip past the reviewing agent.

What was read

The file as it ships in MingyiSecLab/Mingyi-Atlas:

What the static scan said

The scan flagged 3things. The reviewer kept 0 and dismissed 3 as false.

How this review was made

Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.

Produced by agentmods.dev · Sonnet 5 · 7 September 2026

← Back to prompt-injection