{"record":{"id":"493684a74d0a7fe2","repo":"affaan-m/ECC","slug":"potential-prompt-injection-text-100","errorCode":null,"errorMessage":"Potential prompt injection: {text[:100]}","messagePattern":"Potential prompt injection: (.+?)","errorType":"validation","errorClass":"ValueError","httpStatus":null,"severity":"error","filePath":"skills/llm-trading-agent-security/SKILL.md","lineNumber":43,"sourceCode":"\n### Treat prompt injection as a financial attack\n\n```python\nimport re\n\nINJECTION_PATTERNS = [\n    r'ignore (previous|all) instructions',\n    r'new (task|directive|instruction)',\n    r'system prompt',\n    r'send .{0,50} to 0x[0-9a-fA-F]{40}',\n    r'transfer .{0,50} to',\n    r'approve .{0,50} for',\n]\n\ndef sanitize_onchain_data(text: str) -> str:\n    for pattern in INJECTION_PATTERNS:\n        if re.search(pattern, text, re.IGNORECASE):\n            raise ValueError(f\"Potential prompt injection: {text[:100]}\")\n    return text\n```\n\nDo not blindly inject token names, pair labels, webhooks, or social feeds into an execution-capable prompt.\n\n### Hard spend limits\n\n```python\nfrom decimal import Decimal\n\nMAX_SINGLE_TX_USD = Decimal(\"500\")\nMAX_DAILY_SPEND_USD = Decimal(\"2000\")\n\nclass SpendLimitError(Exception):\n    pass\n\nclass SpendLimitGuard:\n    def check_and_record(self, usd_amount: Decimal) -> None:","sourceCodeStart":25,"sourceCodeEnd":61,"githubUrl":"https://github.com/affaan-m/ECC/blob/d8409a4b0813771235555e32e3d8046a73988bfa/skills/llm-trading-agent-security/SKILL.md#L25-L61","documentation":"Illustrative guard from the llm-trading-agent-security skill: sanitize_onchain_data matched on-chain/social/webhook text against known prompt-injection regex patterns and raises with the first 100 chars of the offending text. Untrusted external data that looks like an instruction injection is the input at fault.","triggerScenarios":"Thrown at skills/llm-trading-agent-security/SKILL.md:43 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Never feed raw on-chain or social text into execution-capable prompts","Neutralize (quote/escape) rather than pass through external data","Log flagged inputs to tune patterns and detect attacks"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"d8409a4b0813771235555e32e3d8046a73988bfa","analyzedAt":"2026-08-26T12:15:34.022Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}