affaan-m/ECC · error · ValueError

Potential prompt injection

Error message

Potential prompt injection: {text[:100]}

What it means

Illustrative guard from the llm-trading-agent-security skill: sanitize_onchain_data matched on-chain/social/webhook text against known prompt-injection regex patterns and raises with the first 100 chars of the offending text. Untrusted external data that looks like an instruction injection is the input at fault.

Solutions

  1. Never feed raw on-chain or social text into execution-capable prompts
  2. Neutralize (quote/escape) rather than pass through external data
  3. Log flagged inputs to tune patterns and detect attacks
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at skills/llm-trading-agent-security/SKILL.md:43 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of affaan-m/ECC@d8409a4b08 (2026-08-26). Data as JSON: /api/errors/493684a74d0a7fe2. Report an issue: GitHub.

Appendix: source

Thrown at skills/llm-trading-agent-security/SKILL.md:43

### Treat prompt injection as a financial attack

```python
import re

INJECTION_PATTERNS = [
    r'ignore (previous|all) instructions',
    r'new (task|directive|instruction)',
    r'system prompt',
    r'send .{0,50} to 0x[0-9a-fA-F]{40}',
    r'transfer .{0,50} to',
    r'approve .{0,50} for',
]

def sanitize_onchain_data(text: str) -> str:
    for pattern in INJECTION_PATTERNS:
        if re.search(pattern, text, re.IGNORECASE):
            raise ValueError(f"Potential prompt injection: {text[:100]}")
    return text
```

Do not blindly inject token names, pair labels, webhooks, or social feeds into an execution-capable prompt.

### Hard spend limits

```python
from decimal import Decimal

MAX_SINGLE_TX_USD = Decimal("500")
MAX_DAILY_SPEND_USD = Decimal("2000")

class SpendLimitError(Exception):
    pass

class SpendLimitGuard:
    def check_and_record(self, usd_amount: Decimal) -> None:

View on GitHub (pinned to d8409a4b08)