prompt-engineering
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a Python pattern (
build_review_prompt) that interpolates untrusted data directly into a system prompt, creating a vulnerability to indirect prompt injection. - Ingestion points: The
diffandcontextparameters in the Python function example inSKILL.mdare intended to consume untrusted external data. - Boundary markers: The pattern uses markdown triple backticks as delimiters for the
diffcontent, which can be easily bypassed if the input content itself contains similar delimiters. - Capability inventory: While this skill is documentation, the pattern it teaches is intended for agents performing code analysis, which typically possess file system and search capabilities.
- Sanitization: The provided template pattern does not include any sanitization, escaping, or validation logic for the external inputs before they are combined with instructions.
Audit Metadata