langextract-usage

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Secure Credential Management: The skill provides guidance on using environment variables such as GEMINI_API_KEY and OPENAI_API_KEY for authentication. It consistently uses placeholders like "your_key" and "sk-..." in code snippets, which aligns with secure development practices to avoid accidental secret exposure.
  • Data Ingestion Surface: The library supports fetching and processing content directly from URLs when fetch_urls=True (enabled by default). This represents a primary ingestion point for external data and is a documented feature for information extraction tasks.
  • Indirect Prompt Injection Consideration: The skill facilitates processing unstructured text from external sources through an LLM, which is an inherent surface for indirect prompt injection.
  • Ingestion points: The lx.extract function accepts strings or URLs in SKILL.md and all files in the examples/ directory.
  • Boundary markers: The skill uses prompt_description and few-shot examples to define the task and delimit model behavior.
  • Capability inventory: The library performs network requests to fetch content from URLs and interacts with LLM provider APIs (Gemini, OpenAI, Ollama).
  • Sanitization: The documentation highlights PromptValidationLevel for validating example alignment, though it does not explicitly detail sanitization for the raw input text being processed at runtime.
  • Standard Library and Plugin Architecture: The skill describes a standard installation process via pip and a plugin system using entry-points in pyproject.toml for extending model providers. This modularity is a common pattern in the Python ecosystem and uses standard dynamic loading mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:49 PM
Security Audit — agent-trust-hub — langextract-usage