llm-integration
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains strings such as 'ignore previous instructions' and 'disregard all rules' within its
PromptSanitizerclass andthreat-model.md. These are used as examples of malicious patterns to detect or as part of a regex list for filtering user input, rather than attempts to manipulate the agent's behavior. - [COMMAND_EXECUTION]: The skill provides Python code for interacting with local LLM runtimes (Ollama and llama.cpp). These interactions are restricted to localhost (127.0.0.1) and intended for private AI inference.
- [EXTERNAL_DOWNLOADS]: The skill lists standard, legitimate Python dependencies (llama-cpp-python, ollama, pydantic, jinja2, tiktoken) required for AI development. It emphasizes using versions that include security patches for known CVEs.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies the risk of processing untrusted data and provides specific mitigation strategies, including the use of boundary markers (e.g.,
---BEGIN UNTRUSTED CONTENT---) and specialized sanitization logic for external content. - [PRIVILEGE_ESCALATION]: The skill includes code using the
resourcemodule to set memory limits (resource.setrlimit). This is a security best practice implemented to prevent Denial of Service (DoS) attacks on the host system.
Audit Metadata