llm-engineering-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle untrusted user data and document text, which creates a potential surface for indirect prompt injection. However, the skill explicitly mandates and demonstrates robust security mitigations.
- Ingestion points: Processes external data via parameters like
document_textin extraction functions and{content}placeholders in prompt patterns. - Boundary markers: The skill strongly recommends and uses XML-style delimiters (e.g.,
<document>,<untrusted>,<question>) to separate instructions from data. - Capability inventory: While the skill is granted
Bashaccess, the provided implementation logic is limited to data validation usingpydantic, evaluation scoring, and model interaction via hypothetical API calls. - Sanitization: The instructions include explicit rules for the model to ignore any instructions embedded within data tags and to treat such content strictly as reportable text.
- [EXTERNAL_DOWNLOADS]: The evaluation reference documentation describes a standard CI/CD workflow that involves external resources.
- Evidence: The
references/EVALUATION.mdfile suggests usingactions/checkout@v4andactions/upload-artifact@v4within a GitHub Actions environment. - Source: These are official actions provided by the trusted GitHub Actions organization.
- [COMMAND_EXECUTION]: The skill metadata allows for the use of
pipandpytestwithin aBashenvironment for local testing and dependency management. - Evidence: The CI example in
references/EVALUATION.mdshowspip install -r requirements.txtfollowed by running a local evaluation scriptpython -m evals.run. - Context: This is standard behavior for a development-focused skill intended to support engineering workflows.
Audit Metadata