regex-vs-llm-structured-text
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a hybrid parsing pipeline that is susceptible to indirect prompt injection. Untrusted data from documents is interpolated directly into LLM prompts. Ingestion points: The
process_documentandvalidate_with_llmfunctions inSKILL.mdingest externalcontentandoriginal_text. Boundary markers: The prompt template invalidate_with_llmlacks delimiters or instructions to ignore embedded commands. Capability inventory: No dangerous execution capabilities (subprocess, file-write, network) are present in the provided code snippets. Sanitization: No input validation or escaping is performed on the extracted text before prompt interpolation.
Audit Metadata