vector-search-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The rag_query function in SKILL.md implements a Retrieval-Augmented Generation pipeline that incorporates external data into model prompts.
  • Ingestion points: The function interpolates user-provided question and database-retrieved context into the prompt messages.
  • Boundary markers: The implementation uses text headers ("Context:", "Question:") to separate retrieved data from user input.
  • Capability inventory: The skill includes vector database operations (ChromaDB, pgvector, FAISS) and embedding generation, but does not provide tools for shell execution or filesystem modification.
  • Sanitization: There is no evidence of specific escaping or sanitization of the retrieved chunks before they are formatted into the prompt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — vector-search-patterns