cocoindex

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the cocoindex library and its optional components (such as embeddings, colpali, and lancedb) via standard package managers. It also references several widely recognized third-party libraries for data processing and AI tasks, including sentence-transformers, openai, pymupdf, requests, spacy, and fastapi.
  • [COMMAND_EXECUTION]: Provides detailed documentation for operating the cocoindex CLI, covering commands for resource initialization (setup), data synchronization (update), and project inspection (show, evaluate). It also includes a server command that launches a local utility to facilitate data visualization through a vendor-provided dashboard.
  • [CREDENTIALS_UNSAFE]: The skill provides a default fallback connection string (postgres://cocoindex:cocoindex@localhost/cocoindex) for use in a local development environment if no database URL is configured. While this contains a hardcoded password, it is presented as a standard default for local testing and does not compromise production security.
  • [PROMPT_INJECTION]: The skill includes a specific directive for the agent to ensure users provide valid LLM API keys instead of mock values to ensure the generated code is functional. Additionally, the skill's primary focus on creating data ingestion pipelines from sources like S3 or local files for LLM-based extraction creates a standard surface for indirect prompt injection, which is expected for this class of tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 12:50 PM
Security Audit — agent-trust-hub — cocoindex