anthropic-rag-runtime

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses robust security patterns for data ingestion, specifically utilizing Anthropic's structured document content blocks and Citations API, which effectively separate untrusted retrieved content from system instructions.\n- [SAFE]: A fail-closed grounding gate is implemented to validate model outputs against retrieved context, mitigating risks associated with hallucinations or indirect prompt injection from retrieved data.\n- [SAFE]: Credential management follows best practices by requiring API keys and retriever credentials to be injected at deployment time; no secrets are hardcoded within the skill or its assets.\n- [SAFE]: The skill mandates the redaction of PII and sensitive data from all logs and telemetry, ensuring that retrieved content does not leak through observability channels.\n- [SAFE]: Access control for the retrieval corpus is correctly placed at the retriever level (via ACL filters) rather than being managed through prompt-based instructions, preventing authorization bypass.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — anthropic-rag-runtime