llm-app-patterns

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill provides templates for RAG (Retrieval-Augmented Generation) and ReAct agents that ingest and process external data or tool outputs.
  • Ingestion points: The RAG_PROMPT_TEMPLATE and REACT_PROMPT in SKILL.md interpolate retrieved context and tool observations directly into the LLM prompt.
  • Boundary markers: The provided RAG template includes a directive to "Answer the user's question based ONLY on the following context," which provides a basic boundary but does not fully mitigate sophisticated adversarial inputs.
  • Capability inventory: The agent patterns described include tool execution capabilities and multiple chained LLM calls across all scripts.
  • Sanitization: The code snippets focus on architectural logic and do not implement specific sanitization or escaping mechanisms for external content before interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — llm-app-patterns