sglang
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate documentation for the SGLang project. The instructions, code snippets, and deployment configurations are consistent with industry standards for high-performance model serving.
- [EXTERNAL_DOWNLOADS]: The skill references external resources for installation, including the official SGLang GitHub repository and the FlashInfer wheel registry. These are well-recognized sources within the AI research and engineering community and are necessary for the library's performance features (e.g., CUDA-optimized kernels).
- [INDIRECT_PROMPT_INJECTION]: Several examples demonstrate agents processing untrusted user input (e.g.,
user_queryinagent_workflow). While this creates a theoretical surface for indirect prompt injection, the skill specifically emphasizes the use of SGLang's constrained generation features—such as JSON schemas, regex constraints, and EBNF grammars—which serve as strong programmatic controls to ensure that model outputs adhere to expected formats regardless of the input content.
Audit Metadata