regex-vs-llm-structured-text

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection in its implementation of a hybrid parsing pipeline.
  • Ingestion points: The process_document function in SKILL.md accepts a content string which represents untrusted external text.
  • Boundary markers: In the validate_with_llm function, the input text is interpolated directly into the LLM prompt using an f-string without delimiters (like triple backticks or XML tags) or instructions for the model to ignore any embedded commands within the text.
  • Capability inventory: The skill is limited to text parsing and API calls to an LLM; it does not demonstrate capabilities for file writing, shell execution, or network exfiltration of sensitive files.
  • Sanitization: The implementation does not include any sanitization or validation of the input content before it is processed by the regex or the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM