rag-architect
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: In
references/embedding-models.md, theLateChunkerclass utilizes thetrust_remote_code=Trueparameter when callingAutoModel.from_pretrained. This is a known feature of the Transformers library required by specific models (such as Jina embeddings) to execute repository-defined code, which represents a potential attack vector if an untrusted model is loaded. - [INDIRECT_PROMPT_INJECTION]: The skill documents the creation of systems that ingest untrusted data into AI contexts, creating a potential surface for indirect prompt injection.
- Ingestion points: Document ingestion and indexing examples in
SKILL.mdandreferences/chunking-strategies.md. - Boundary markers: Code snippets for context interpolation (e.g.,
compress_retrieved_contextinreferences/retrieval-optimization.md) do not demonstrate robust delimiting or instructions to ignore embedded content. - Capability inventory: The architectural examples include network operations (OpenAI, Qdrant, Pinecone, Cohere, Weaviate) and file-system access for caching in
references/embedding-models.md. - Sanitization: No specific sanitization or validation of retrieved content is shown before it is passed to the LLM judge or generation component.
Audit Metadata