prompt-template
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
PromptTemplate.rendermethod inSKILL.mdimplements a simple string substitution mechanism (result.replace(f"{{{key}}}", str(value))) that facilitates the inclusion of external data into agent prompts. - Ingestion points: The
rendermethod accepts arbitrarykwargsthat are placed directly into template placeholders. - Boundary markers: The provided templates (e.g.,
agent_base.yaml,code_review.yaml) use header markers like## Taskbut do not include explicit delimiters or instructions for the LLM to ignore embedded commands in the interpolated data. - Capability inventory: The skill itself focuses on string manipulation and local file reading, but the prompts it generates are used to control the agent's behavior across all its available tools.
- Sanitization: There is no evidence of validation, escaping, or filtering of the content provided in the
kwargsbefore interpolation. - [SAFE]: The implementation uses
yaml.safe_load()for parsing template files, following best practices to prevent unsafe deserialization vulnerabilities. - [SAFE]: No network operations, hardcoded credentials, privilege escalation attempts, or persistence mechanisms were detected in the provided Python implementation or YAML examples.
Audit Metadata