senior-ml-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for building LLM applications that are vulnerable to indirect prompt injection if implemented as shown.
- Ingestion points: Untrusted data enters the agent context through the
{user_input}placeholder in theFEW_SHOT_TEMPLATE(references/llm_integration_guide.md) and the{question}/{context}placeholders in the_build_promptmethod (references/rag_system_architecture.md). - Boundary markers: The provided prompt templates lack clear delimiters (e.g., XML tags or triple quotes) to separate instructions from user-provided data.
- Capability inventory: The skill includes Python scripts for model deployment (
scripts/model_deployment_pipeline.py) and monitoring (scripts/ml_monitoring_suite.py), though these scripts currently contain only boilerplate logic and do not directly process the vulnerable prompts. - Sanitization: The reference guides do not demonstrate or recommend techniques for escaping or validating external content before interpolation into prompts.
Audit Metadata