skool-rag

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes community-generated content (posts and comments) and interpolates it into the prompt for the Claude model.
  • Ingestion points: scripts/skool_rag_prepare.py reads data from local JSON files containing community posts and comments.
  • Boundary markers: scripts/skool_rag_query.py uses horizontal rules (---) and markdown headers (### Source i) to delimit sources within the context window. The system prompt also includes instructions to "Answer based ONLY on the provided context."
  • Capability inventory: The skill is capable of querying a vector database (Pinecone) and generating responses using LLMs (Claude, OpenAI).
  • Sanitization: There is no explicit logic to sanitize or filter the scraped content for embedded instructions or adversarial triggers before it is passed to the LLM.
  • [COMMAND_EXECUTION]: The skill's primary workflow involves executing local Python scripts that handle data processing and API communication.
  • Evidence: SKILL.md provides shell commands such as python3 ./scripts/skool_rag_prepare.py and python3 ./scripts/skool_rag_index.py for the agent or user to execute.
  • [EXTERNAL_DOWNLOADS]: The scripts require several external Python libraries to interact with AI services and vector databases.
  • Evidence: scripts/skool_rag_index.py and scripts/skool_rag_query.py check for the presence of openai, pinecone-client, anthropic, and cohere. These are well-known and established service providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:55 PM