skills/aeondave/malskill/langchain-py/Gen Agent Trust Hub

langchain-py

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive guidelines for LangChain Python agent design, including single-agent and multi-agent architectures. The provided code snippets follow standard development practices and do not contain hidden or dangerous commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a surface for indirect prompt injection by integrating external web search capabilities.
  • Ingestion points: Untrusted data is ingested from the web via the Tavily search tool described in references/tavily-integration.md.
  • Boundary markers: The skill does not explicitly define prompt delimiters for external content, though it recommends returning summarized and cited findings to the supervisor to limit context exposure.
  • Capability inventory: Agents are equipped with tool-calling capabilities to interact with search APIs, calendar tools, and email services as described in references/subagents-supervisor.md.
  • Sanitization: The skill instructions do not specify content sanitization or filtering for search results, which is a standard characteristic of search-oriented agent designs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — langchain-py