langchain-py
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides comprehensive guidelines for LangChain Python agent design, including single-agent and multi-agent architectures. The provided code snippets follow standard development practices and do not contain hidden or dangerous commands.
- [INDIRECT_PROMPT_INJECTION]: The skill implements a surface for indirect prompt injection by integrating external web search capabilities.
- Ingestion points: Untrusted data is ingested from the web via the Tavily search tool described in
references/tavily-integration.md. - Boundary markers: The skill does not explicitly define prompt delimiters for external content, though it recommends returning summarized and cited findings to the supervisor to limit context exposure.
- Capability inventory: Agents are equipped with tool-calling capabilities to interact with search APIs, calendar tools, and email services as described in
references/subagents-supervisor.md. - Sanitization: The skill instructions do not specify content sanitization or filtering for search results, which is a standard characteristic of search-oriented agent designs.
Audit Metadata