cost-aware-llm-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes a pipeline that ingests untrusted external data which is then passed to an LLM client.
- Ingestion points: The
processfunction and message construction inSKILL.mdtake raw strings as input. - Boundary markers: The provided code snippets lack explicit boundary markers or instructions for the agent to ignore embedded commands within the user-provided text.
- Capability inventory: The pipeline performs network operations to LLM provider APIs via the
client.messages.createcall. - Sanitization: No sanitization or escaping of the user-provided strings is demonstrated before interpolation into the prompt templates.
Audit Metadata