llm-app-patterns
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides templates for RAG (Retrieval-Augmented Generation) and ReAct agents that ingest and process external data or tool outputs.
- Ingestion points: The
RAG_PROMPT_TEMPLATEandREACT_PROMPTinSKILL.mdinterpolate retrieved context and tool observations directly into the LLM prompt. - Boundary markers: The provided RAG template includes a directive to "Answer the user's question based ONLY on the following context," which provides a basic boundary but does not fully mitigate sophisticated adversarial inputs.
- Capability inventory: The agent patterns described include tool execution capabilities and multiple chained LLM calls across all scripts.
- Sanitization: The code snippets focus on architectural logic and do not implement specific sanitization or escaping mechanisms for external content before interpolation.
Audit Metadata