llm-architect
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The static analysis flag for prompt injection in
references/sharp_edges.mdis a false positive. The content describes prompt injection as a security risk in RAG systems for educational purposes and provides specific code solutions to mitigate it, rather than attempting to inject instructions into the agent. - [EXTERNAL_DOWNLOADS]: The skill code examples reference standard, well-known libraries such as
tiktoken,tenacity,anthropic, andlangchain. No untrusted external sources or suspicious downloads were detected. - [INDIRECT_PROMPT_INJECTION]: The skill provides best-practice guidance for preventing indirect prompt injection in LLM applications. It includes examples of using XML delimiters for untrusted content and secondary LLM calls for injection detection, which are strong defensive patterns.
- [DATA_EXFILTRATION]: No evidence of unauthorized data access or exfiltration. Code snippets demonstrate standard RAG and API interaction patterns without accessing sensitive local files or environment variables.
Audit Metadata