regex-vs-llm-structured-text
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection in its implementation of a hybrid parsing pipeline.
- Ingestion points: The
process_documentfunction inSKILL.mdaccepts acontentstring which represents untrusted external text. - Boundary markers: In the
validate_with_llmfunction, the input text is interpolated directly into the LLM prompt using an f-string without delimiters (like triple backticks or XML tags) or instructions for the model to ignore any embedded commands within the text. - Capability inventory: The skill is limited to text parsing and API calls to an LLM; it does not demonstrate capabilities for file writing, shell execution, or network exfiltration of sensitive files.
- Sanitization: The implementation does not include any sanitization or validation of the input content before it is processed by the regex or the LLM.
Audit Metadata