llm-engineering-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to handle untrusted user data and document text, which creates a potential surface for indirect prompt injection. However, the skill explicitly mandates and demonstrates robust security mitigations.
  • Ingestion points: Processes external data via parameters like document_text in extraction functions and {content} placeholders in prompt patterns.
  • Boundary markers: The skill strongly recommends and uses XML-style delimiters (e.g., <document>, <untrusted>, <question>) to separate instructions from data.
  • Capability inventory: While the skill is granted Bash access, the provided implementation logic is limited to data validation using pydantic, evaluation scoring, and model interaction via hypothetical API calls.
  • Sanitization: The instructions include explicit rules for the model to ignore any instructions embedded within data tags and to treat such content strictly as reportable text.
  • [EXTERNAL_DOWNLOADS]: The evaluation reference documentation describes a standard CI/CD workflow that involves external resources.
  • Evidence: The references/EVALUATION.md file suggests using actions/checkout@v4 and actions/upload-artifact@v4 within a GitHub Actions environment.
  • Source: These are official actions provided by the trusted GitHub Actions organization.
  • [COMMAND_EXECUTION]: The skill metadata allows for the use of pip and pytest within a Bash environment for local testing and dependency management.
  • Evidence: The CI example in references/EVALUATION.md shows pip install -r requirements.txt followed by running a local evaluation script python -m evals.run.
  • Context: This is standard behavior for a development-focused skill intended to support engineering workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:12 AM
Security Audit — agent-trust-hub — llm-engineering-expert