skills/rohitg00/pro-workflow/llm-gate/Gen Agent Trust Hub

llm-gate

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for using LLM hooks that interpolate $ARGUMENTS directly into prompts without sufficient isolation.
  • Ingestion points: The $ARGUMENTS placeholder in SKILL.md examples, which represents user-controlled data such as commit messages, file contents, and command arguments.
  • Boundary markers: The provided prompt templates lack delimiters (e.g., XML tags or unique markers) or specific instructions to the secondary LLM to ignore embedded commands within the tool arguments.
  • Capability inventory: These gates are intended to monitor and block critical tool operations including Bash (git, rm) and Write.
  • Sanitization: The skill does not implement or recommend sanitization or filtering of external content before it is interpolated into the prompt, making it possible for adversarial input to influence the gate's success/failure decision.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — llm-gate