rag-architect

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: In references/embedding-models.md, the LateChunker class utilizes the trust_remote_code=True parameter when calling AutoModel.from_pretrained. This is a known feature of the Transformers library required by specific models (such as Jina embeddings) to execute repository-defined code, which represents a potential attack vector if an untrusted model is loaded.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents the creation of systems that ingest untrusted data into AI contexts, creating a potential surface for indirect prompt injection.
  • Ingestion points: Document ingestion and indexing examples in SKILL.md and references/chunking-strategies.md.
  • Boundary markers: Code snippets for context interpolation (e.g., compress_retrieved_context in references/retrieval-optimization.md) do not demonstrate robust delimiting or instructions to ignore embedded content.
  • Capability inventory: The architectural examples include network operations (OpenAI, Qdrant, Pinecone, Cohere, Weaviate) and file-system access for caching in references/embedding-models.md.
  • Sanitization: No specific sanitization or validation of retrieved content is shown before it is passed to the LLM judge or generation component.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — rag-architect