llm-patterns

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a template pattern that interpolates untrusted data directly into an LLM prompt, creating a surface for indirect prompt injection.
  • Ingestion points: The classifyTicketPrompt function in core/prompts/classify.ts takes a raw string input (ticket) and embeds it into the prompt.
  • Boundary markers: The prompt template lacks clear delimiters (like XML tags or triple quotes) or explicit system instructions to ignore embedded commands within the ticket content.
  • Capability inventory: The generated prompt is processed by the llmCall function, which performs network operations to the Anthropic API and executes JSON.parse on the response.
  • Sanitization: There is no evidence of input escaping, length limiting, or content filtering on the ticket variable before it is interpolated into the final prompt string.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 12:38 PM