cocoindex
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the
cocoindexlibrary and its optional components (such asembeddings,colpali, andlancedb) via standard package managers. It also references several widely recognized third-party libraries for data processing and AI tasks, includingsentence-transformers,openai,pymupdf,requests,spacy, andfastapi. - [COMMAND_EXECUTION]: Provides detailed documentation for operating the
cocoindexCLI, covering commands for resource initialization (setup), data synchronization (update), and project inspection (show,evaluate). It also includes aservercommand that launches a local utility to facilitate data visualization through a vendor-provided dashboard. - [CREDENTIALS_UNSAFE]: The skill provides a default fallback connection string (
postgres://cocoindex:cocoindex@localhost/cocoindex) for use in a local development environment if no database URL is configured. While this contains a hardcoded password, it is presented as a standard default for local testing and does not compromise production security. - [PROMPT_INJECTION]: The skill includes a specific directive for the agent to ensure users provide valid LLM API keys instead of mock values to ensure the generated code is functional. Additionally, the skill's primary focus on creating data ingestion pipelines from sources like S3 or local files for LLM-based extraction creates a standard surface for indirect prompt injection, which is expected for this class of tool.
Audit Metadata