langchain-prompt-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides explicit guidance on mitigating indirect prompt injection in RAG pipelines. It teaches the use of structural XML boundaries (e.g., <document> tags) and specific system instructions to ensure the model treats ingested data as content rather than executable commands.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, reputable packages from the LangChain ecosystem (langchain-core, langsmith, langchain-anthropic, langchain-openai) and well-known services (LangSmith). All downloads are from trusted public registries.
  • [SAFE]: No obfuscation, data exfiltration, or unauthorized privilege escalation patterns were found. The skill promotes secure development practices, such as managing secrets via environment variables and using immutable commit hashes for prompt versioning in production.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:44 AM
Security Audit — agent-trust-hub — langchain-prompt-engineering