senior-ml-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns and scaffolds for LLM and RAG integrations that interpolate untrusted external data into prompts without explicit sanitization or boundary markers.
- Ingestion points: The sentiment classification template in references/llm_integration_guide.md and document content retrieval in references/rag_system_architecture.md.
- Boundary markers: Templates do not include delimiters (e.g., XML tags or triple quotes) or 'ignore' instructions for the interpolated data.
- Capability inventory: The skill generates infrastructure manifests (Docker/Kubernetes) and provides logic for interacting with LLM APIs and vector databases.
- Sanitization: No input filtering or escaping is implemented in the provided scaffolding code.
Audit Metadata