rag-architect
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes utilities (
chunking_optimizer.py,retrieval_evaluator.py) that ingest untrusted text data from user-specified local directories for analysis. While the scripts perform purely statistical and algorithmic processing (TF-IDF, chunk size analysis) and do not directly call an LLM, the data they process is intended to be integrated into agent contexts where embedded instructions could potentially influence downstream AI behavior. - Ingestion points: The
DocumentCorpusclass inchunking_optimizer.pyand theload_corpusfunction inretrieval_evaluator.pyread files from local paths provided via command-line arguments. - Boundary markers: The scripts do not implement specific delimiters or 'ignore' instructions for the content being processed, treating all document text as raw input for analysis.
- Capability inventory: Capabilities are restricted to local file system read/write operations (for reports/logs) using standard Python I/O. There are no network operations, subprocess executions, or dynamic code evaluation (
eval/exec) calls. - Sanitization: The scripts use regex-based tokenization and basic string cleanup, which is appropriate for their analytical purpose but does not filter for natural language instruction patterns.
Audit Metadata