skool-rag
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes community-generated content (posts and comments) and interpolates it into the prompt for the Claude model.
- Ingestion points:
scripts/skool_rag_prepare.pyreads data from local JSON files containing community posts and comments. - Boundary markers:
scripts/skool_rag_query.pyuses horizontal rules (---) and markdown headers (### Source i) to delimit sources within the context window. The system prompt also includes instructions to "Answer based ONLY on the provided context." - Capability inventory: The skill is capable of querying a vector database (Pinecone) and generating responses using LLMs (Claude, OpenAI).
- Sanitization: There is no explicit logic to sanitize or filter the scraped content for embedded instructions or adversarial triggers before it is passed to the LLM.
- [COMMAND_EXECUTION]: The skill's primary workflow involves executing local Python scripts that handle data processing and API communication.
- Evidence:
SKILL.mdprovides shell commands such aspython3 ./scripts/skool_rag_prepare.pyandpython3 ./scripts/skool_rag_index.pyfor the agent or user to execute. - [EXTERNAL_DOWNLOADS]: The scripts require several external Python libraries to interact with AI services and vector databases.
- Evidence:
scripts/skool_rag_index.pyandscripts/skool_rag_query.pycheck for the presence ofopenai,pinecone-client,anthropic, andcohere. These are well-known and established service providers.
Audit Metadata