llm-integration
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
retrieveAndGeneratefunction inSKILL.mddemonstrates a RAG (Retrieval-Augmented Generation) pattern that interpolates untrusted data from an external vector database and a user query into the model prompt. - Ingestion points: The
context(retrieved fromvectorDb) andquery(user input) variables inSKILL.md. - Boundary markers: The prompt construction uses simple text labels like
Context:\n${context}but lacks robust delimiters or explicit instructions to the model to ignore potential instructions embedded within the retrieved context. - Capability inventory: The
agentLoopinSKILL.mdimplements function calling (executeToolCall), which could be misdirected if an injection occurs via the prompt surface. - Sanitization: The provided code snippets do not implement sanitization, filtering, or escaping for external content before it is interpolated into the prompt template, although the 'Anti-Patterns' section correctly identifies a lack of validation as a risk.
Audit Metadata