llm-app-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes links to official documentation and public repositories for well-known services and trusted organizations, including the Anthropic Cookbook, LangChain, LlamaIndex, and the Dify platform. These are provided as informational resources for developers.
  • [INDIRECT_PROMPT_INJECTION]: The architectural patterns described in the skill, such as generate_with_rag and ReActAgent in SKILL.md, involve interpolating external data (retrieved context) and user queries into prompt templates. While these are standard design patterns for AI applications, they highlight the inherent attack surface for indirect prompt injection that developers must secure when implementing these patterns.
  • Ingestion points: User queries and retrieved context docs in the generate_with_rag function.
  • Boundary markers: The RAG_PROMPT_TEMPLATE uses text-based instructions ("Answer ... based ONLY on the following context") but lacks structural delimiters like XML tags.
  • Capability inventory: The described patterns utilize abstract llm.generate calls; the skill itself does not provide executable tools or perform system operations.
  • Sanitization: The provided code snippets demonstrate basic string formatting without explicit input sanitization or validation, which is typical for illustrative architectural examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — llm-app-patterns