prompt-template

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The PromptTemplate.render method in SKILL.md implements a simple string substitution mechanism (result.replace(f"{{{key}}}", str(value))) that facilitates the inclusion of external data into agent prompts.
  • Ingestion points: The render method accepts arbitrary kwargs that are placed directly into template placeholders.
  • Boundary markers: The provided templates (e.g., agent_base.yaml, code_review.yaml) use header markers like ## Task but do not include explicit delimiters or instructions for the LLM to ignore embedded commands in the interpolated data.
  • Capability inventory: The skill itself focuses on string manipulation and local file reading, but the prompts it generates are used to control the agent's behavior across all its available tools.
  • Sanitization: There is no evidence of validation, escaping, or filtering of the content provided in the kwargs before interpolation.
  • [SAFE]: The implementation uses yaml.safe_load() for parsing template files, following best practices to prevent unsafe deserialization vulnerabilities.
  • [SAFE]: No network operations, hardcoded credentials, privilege escalation attempts, or persistence mechanisms were detected in the provided Python implementation or YAML examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:36 PM