project-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a methodology for building systems that ingest data from external sources and process it using LLMs, which creates a surface for indirect prompt injection.
- Ingestion points: Data is fetched from external APIs, databases, or files during the 'Acquire' stage (e.g., in
scripts/pipeline_template.pyvia thefetch_items_from_sourcefunction). - Boundary markers: The prompt templates (e.g.,
PROMPT_TEMPLATEinscripts/pipeline_template.py) use structure markers like '---' and headers, but do not include explicit instructions for the model to ignore potential commands embedded within the fetched content. - Capability inventory: The methodology suggests granting agents capabilities such as shell command execution and SQL queries (referenced in
SKILL.mdand the Vercel case study). The provided Python scriptscripts/pipeline_template.pyuses standard file system operations and thread pooling. - Sanitization: The provided examples do not implement specific input sanitization or filtering to remove potential injection payloads from the data before it is interpolated into LLM prompts.
- [SAFE]: All external references target well-known and trusted sources, including official GitHub repositories for Anthropic, and case studies involving established technology companies like Vercel and individuals like Andrej Karpathy. Documentation of these resources is neutral and aligns with the educational purpose of the skill.
Audit Metadata