regex-vs-llm-structured-text
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines a hybrid parsing pipeline that creates an indirect prompt injection surface. The
validate_with_llmfunction inSKILL.mdinterpolates untrusted input (original_text) directly into an LLM prompt template without using delimiters or instruction-override guards. - Ingestion points: The
process_documentandvalidate_with_llmfunctions inSKILL.mdaccept arbitrary document content. - Boundary markers: Absent. The source text is placed directly into the prompt string without clear separators or 'ignore embedded instructions' headers.
- Capability inventory: The provided code snippets do not include dangerous capabilities such as file system writing or arbitrary command execution; the impact is limited to the LLM returning incorrect parsing results.
- Sanitization: The implementation lacks sanitization or validation of the input text before it is sent to the LLM validator.
Audit Metadata