rag-architect

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external documents (e.g., using RecursiveCharacterTextSplitter and create_documents), which creates a surface for indirect prompt injection if the processed content contains malicious instructions.
  • Ingestion points: Document content is processed in SKILL.md (via raw_docs) and references/chunking-strategies.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the examples.
  • Capability inventory: The skill utilizes file system access for document reading and performs network operations via various API clients (OpenAI, Cohere, Qdrant).
  • Sanitization: No content sanitization or filtering is implemented before the data is processed or summarized by an LLM.
  • [REMOTE_CODE_EXECUTION]: The LateChunker implementation in references/chunking-strategies.md uses trust_remote_code=True to load the jinaai/jina-embeddings-v2-base-en model from Hugging Face. This setting allows the execution of custom code provided in the model's repository during the loading process, representing a remote code execution vector from a well-known service.
  • [METADATA_POISONING]: The SKILL.md frontmatter identifies the author as https://github.com/Jeffallan, which does not match the platform's registered author metadata (austin-aziz).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:06 AM
Security Audit — agent-trust-hub — rag-architect