rag-architect
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external documents (e.g., using
RecursiveCharacterTextSplitterandcreate_documents), which creates a surface for indirect prompt injection if the processed content contains malicious instructions. - Ingestion points: Document content is processed in
SKILL.md(viaraw_docs) andreferences/chunking-strategies.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the examples.
- Capability inventory: The skill utilizes file system access for document reading and performs network operations via various API clients (OpenAI, Cohere, Qdrant).
- Sanitization: No content sanitization or filtering is implemented before the data is processed or summarized by an LLM.
- [REMOTE_CODE_EXECUTION]: The
LateChunkerimplementation inreferences/chunking-strategies.mdusestrust_remote_code=Trueto load thejinaai/jina-embeddings-v2-base-enmodel from Hugging Face. This setting allows the execution of custom code provided in the model's repository during the loading process, representing a remote code execution vector from a well-known service. - [METADATA_POISONING]: The
SKILL.mdfrontmatter identifies the author ashttps://github.com/Jeffallan, which does not match the platform's registered author metadata (austin-aziz).
Audit Metadata