anthropic-rag-runtime
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses robust security patterns for data ingestion, specifically utilizing Anthropic's structured document content blocks and Citations API, which effectively separate untrusted retrieved content from system instructions.\n- [SAFE]: A fail-closed grounding gate is implemented to validate model outputs against retrieved context, mitigating risks associated with hallucinations or indirect prompt injection from retrieved data.\n- [SAFE]: Credential management follows best practices by requiring API keys and retriever credentials to be injected at deployment time; no secrets are hardcoded within the skill or its assets.\n- [SAFE]: The skill mandates the redaction of PII and sensitive data from all logs and telemetry, ensuring that retrieved content does not leak through observability channels.\n- [SAFE]: Access control for the retrieval corpus is correctly placed at the retriever level (via ACL filters) rather than being managed through prompt-based instructions, preventing authorization bypass.
Audit Metadata