llm-gate
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for using LLM hooks that interpolate $ARGUMENTS directly into prompts without sufficient isolation.
- Ingestion points: The $ARGUMENTS placeholder in SKILL.md examples, which represents user-controlled data such as commit messages, file contents, and command arguments.
- Boundary markers: The provided prompt templates lack delimiters (e.g., XML tags or unique markers) or specific instructions to the secondary LLM to ignore embedded commands within the tool arguments.
- Capability inventory: These gates are intended to monitor and block critical tool operations including Bash (git, rm) and Write.
- Sanitization: The skill does not implement or recommend sanitization or filtering of external content before it is interpolated into the prompt, making it possible for adversarial input to influence the gate's success/failure decision.
Audit Metadata