regex-vs-llm-structured-text

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a hybrid parsing pipeline that is susceptible to indirect prompt injection. Untrusted data from documents is interpolated directly into LLM prompts. Ingestion points: The process_document and validate_with_llm functions in SKILL.md ingest external content and original_text. Boundary markers: The prompt template in validate_with_llm lacks delimiters or instructions to ignore embedded commands. Capability inventory: No dangerous execution capabilities (subprocess, file-write, network) are present in the provided code snippets. Sanitization: No input validation or escaping is performed on the extracted text before prompt interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — regex-vs-llm-structured-text