llm-patterns
Pass
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill implements a template pattern that interpolates untrusted data directly into an LLM prompt, creating a surface for indirect prompt injection.
- Ingestion points: The
classifyTicketPromptfunction incore/prompts/classify.tstakes a raw string input (ticket) and embeds it into the prompt. - Boundary markers: The prompt template lacks clear delimiters (like XML tags or triple quotes) or explicit system instructions to ignore embedded commands within the ticket content.
- Capability inventory: The generated prompt is processed by the
llmCallfunction, which performs network operations to the Anthropic API and executesJSON.parseon the response. - Sanitization: There is no evidence of input escaping, length limiting, or content filtering on the
ticketvariable before it is interpolated into the final prompt string.
Audit Metadata