senior-ml-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for building LLM applications that are vulnerable to indirect prompt injection if implemented as shown.
  • Ingestion points: Untrusted data enters the agent context through the {user_input} placeholder in the FEW_SHOT_TEMPLATE (references/llm_integration_guide.md) and the {question}/{context} placeholders in the _build_prompt method (references/rag_system_architecture.md).
  • Boundary markers: The provided prompt templates lack clear delimiters (e.g., XML tags or triple quotes) to separate instructions from user-provided data.
  • Capability inventory: The skill includes Python scripts for model deployment (scripts/model_deployment_pipeline.py) and monitoring (scripts/ml_monitoring_suite.py), though these scripts currently contain only boilerplate logic and do not directly process the vulnerable prompts.
  • Sanitization: The reference guides do not demonstrate or recommend techniques for escaping or validating external content before interpolation into prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM