regex-vs-llm-structured-text
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a hybrid parsing pipeline that passes raw, potentially untrusted source text directly into an LLM prompt for validation.
- Ingestion points: The
original_textvariable in thevalidate_with_llmfunction (SKILL.md) accepts external content. - Boundary markers: The prompt template lacks explicit delimiters or structural markers (such as XML tags or triple backticks) to isolate the untrusted
original_textfrom the core instructions. - Capability inventory: The skill performs only LLM text validation; it does not utilize tool capabilities, file system access, or shell commands.
- Sanitization: No sanitization or escaping of the input text is implemented before prompt interpolation.
- [SAFE]: The provided code snippets are purely instructional and rely on standard Python libraries (re, dataclasses). No hardcoded credentials, malicious network exfiltration, or persistence mechanisms were detected.
Audit Metadata