llm-app-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes links to official documentation and public repositories for well-known services and trusted organizations, including the Anthropic Cookbook, LangChain, LlamaIndex, and the Dify platform. These are provided as informational resources for developers.
- [INDIRECT_PROMPT_INJECTION]: The architectural patterns described in the skill, such as
generate_with_ragandReActAgentinSKILL.md, involve interpolating external data (retrieved context) and user queries into prompt templates. While these are standard design patterns for AI applications, they highlight the inherent attack surface for indirect prompt injection that developers must secure when implementing these patterns. - Ingestion points: User queries and retrieved context docs in the
generate_with_ragfunction. - Boundary markers: The
RAG_PROMPT_TEMPLATEuses text-based instructions ("Answer ... based ONLY on the following context") but lacks structural delimiters like XML tags. - Capability inventory: The described patterns utilize abstract
llm.generatecalls; the skill itself does not provide executable tools or perform system operations. - Sanitization: The provided code snippets demonstrate basic string formatting without explicit input sanitization or validation, which is typical for illustrative architectural examples.
Audit Metadata