sota-llm-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines an architecture for processing untrusted data from multiple sources, creating a potential vulnerability surface.
- Ingestion points: User queries, retrieved context in RAG pipelines (rules/03), and tool execution results in agent loops (rules/04).
- Boundary markers: Recommends structured XML-style delimiters and explicit 'untrusted' labeling as detailed in rules/02 §4.
- Capability inventory: The systems described involve tool execution (including broad tools like bash/SQL), provider API network calls, and file system operations for memory storage.
- Sanitization: Recommends delimiter escaping (esc()) and structured output validation (rules/02 §6) to mitigate parsing failures.
- [METADATA_POISONING]: The skill uses a 'mid-2026' persona throughout its documentation, presenting anachronistic and potentially inaccurate information as verified fact.
- Evidence: The frontmatter and multiple rules files (e.g., rules/02, rules/05) claim to be verified in June/July 2026 and provide specific pricing and tokenization data as current reality, which may mislead an agent's technical or cost-based decision-making.
- [DYNAMIC_EXECUTION]: The skill defines agentic loops where the model dynamically decides on actions and tool calls.
- Evidence: Rule 04 describes autonomous loops with machine-decidable done-criteria and dynamic tool selection, creating a surface for autonomous behavior that requires strict harness-level budgets and human-in-the-loop gates.
Audit Metadata