sota-llm-engineering

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for processing untrusted data from multiple sources, creating a potential vulnerability surface.
  • Ingestion points: User queries, retrieved context in RAG pipelines (rules/03), and tool execution results in agent loops (rules/04).
  • Boundary markers: Recommends structured XML-style delimiters and explicit 'untrusted' labeling as detailed in rules/02 §4.
  • Capability inventory: The systems described involve tool execution (including broad tools like bash/SQL), provider API network calls, and file system operations for memory storage.
  • Sanitization: Recommends delimiter escaping (esc()) and structured output validation (rules/02 §6) to mitigate parsing failures.
  • [METADATA_POISONING]: The skill uses a 'mid-2026' persona throughout its documentation, presenting anachronistic and potentially inaccurate information as verified fact.
  • Evidence: The frontmatter and multiple rules files (e.g., rules/02, rules/05) claim to be verified in June/July 2026 and provide specific pricing and tokenization data as current reality, which may mislead an agent's technical or cost-based decision-making.
  • [DYNAMIC_EXECUTION]: The skill defines agentic loops where the model dynamically decides on actions and tool calls.
  • Evidence: Rule 04 describes autonomous loops with machine-decidable done-criteria and dynamic tool selection, creating a surface for autonomous behavior that requires strict harness-level budgets and human-in-the-loop gates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 02:46 PM
Security Audit — agent-trust-hub — sota-llm-engineering