llm-integration

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains strings such as 'ignore previous instructions' and 'disregard all rules' within its PromptSanitizer class and threat-model.md. These are used as examples of malicious patterns to detect or as part of a regex list for filtering user input, rather than attempts to manipulate the agent's behavior.
  • [COMMAND_EXECUTION]: The skill provides Python code for interacting with local LLM runtimes (Ollama and llama.cpp). These interactions are restricted to localhost (127.0.0.1) and intended for private AI inference.
  • [EXTERNAL_DOWNLOADS]: The skill lists standard, legitimate Python dependencies (llama-cpp-python, ollama, pydantic, jinja2, tiktoken) required for AI development. It emphasizes using versions that include security patches for known CVEs.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies the risk of processing untrusted data and provides specific mitigation strategies, including the use of boundary markers (e.g., ---BEGIN UNTRUSTED CONTENT---) and specialized sanitization logic for external content.
  • [PRIVILEGE_ESCALATION]: The skill includes code using the resource module to set memory limits (resource.setrlimit). This is a security best practice implemented to prevent Denial of Service (DoS) attacks on the host system.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — llm-integration