rag-architect
Warn
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The references/chunking-strategies.md file contains an implementation example for LateChunker that uses the trust_remote_code=True flag with AutoModel.from_pretrained. This configuration allows the model repository to execute arbitrary Python code on the host machine, which presents a security risk if the repository is untrusted or compromised.
- [REMOTE_CODE_EXECUTION]: The inclusion of code snippets facilitating the loading of remote models with execution privileges (trust_remote_code=True) provides a pathway for remote code execution.
- [INDIRECT_PROMPT_INJECTION]: The skill implements a retrieval-augmented generation (RAG) workflow that ingests potentially untrusted external data.
- Ingestion points: The workflow in SKILL.md and references/chunking-strategies.md processes raw document content (raw_docs, document_text) for indexing and retrieval.
- Boundary markers: The code examples for building retrieval pipelines do not demonstrate the use of delimiters or protective instructions to prevent the LLM from following commands embedded within retrieved documents.
- Capability inventory: The skill utilizes tools for network communication (OpenAI, Cohere APIs) and database operations (Pinecone, Qdrant, Weaviate), creating a risk that injected instructions could trigger unauthorized actions.
- Sanitization: No sanitization or filtering logic is present in the retrieval examples to clean or validate external content before it is used in prompt context.
Audit Metadata