instructor

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill provides legitimate documentation and usage examples for the 'instructor' library, focusing on structured data extraction and validation using Pydantic models. It includes helpful agent operating procedures and integrity rules to ensure safe usage.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process LLM-generated text into structured formats, which represents a potential attack surface for indirect prompt injection.
  • Ingestion points: Free-form text input is processed via client.messages.create in various files, such as SKILL.md and common-patterns.md.
  • Boundary markers: The provided code examples demonstrate standard role-based messaging without explicit delimiters or instructions for the agent to ignore embedded commands within the processed data.
  • Capability inventory: The analysis of the provided documentation and code snippets shows no capabilities for subprocess execution, file system writes, or network operations beyond standard LLM API calls.
  • Sanitization: The library utilizes Pydantic schemas (e.g., the User, Article, and Event models) as the primary mechanism for sanitizing and enforcing the structure of LLM outputs.
  • [EXTERNAL_DOWNLOADS]: Documentation and installation instructions refer to established and widely-used Python packages from official registries, including instructor, pydantic, openai, and anthropic.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — instructor