langextract-usage
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Secure Credential Management: The skill provides guidance on using environment variables such as
GEMINI_API_KEYandOPENAI_API_KEYfor authentication. It consistently uses placeholders like"your_key"and"sk-..."in code snippets, which aligns with secure development practices to avoid accidental secret exposure. - Data Ingestion Surface: The library supports fetching and processing content directly from URLs when
fetch_urls=True(enabled by default). This represents a primary ingestion point for external data and is a documented feature for information extraction tasks. - Indirect Prompt Injection Consideration: The skill facilitates processing unstructured text from external sources through an LLM, which is an inherent surface for indirect prompt injection.
- Ingestion points: The
lx.extractfunction accepts strings or URLs inSKILL.mdand all files in theexamples/directory. - Boundary markers: The skill uses
prompt_descriptionand few-shotexamplesto define the task and delimit model behavior. - Capability inventory: The library performs network requests to fetch content from URLs and interacts with LLM provider APIs (Gemini, OpenAI, Ollama).
- Sanitization: The documentation highlights
PromptValidationLevelfor validating example alignment, though it does not explicitly detail sanitization for the raw input text being processed at runtime. - Standard Library and Plugin Architecture: The skill describes a standard installation process via
pipand a plugin system usingentry-pointsinpyproject.tomlfor extending model providers. This modularity is a common pattern in the Python ecosystem and uses standard dynamic loading mechanisms.
Audit Metadata