rag-architect

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The references/chunking-strategies.md file contains an implementation example for LateChunker that uses the trust_remote_code=True flag with AutoModel.from_pretrained. This configuration allows the model repository to execute arbitrary Python code on the host machine, which presents a security risk if the repository is untrusted or compromised.
  • [REMOTE_CODE_EXECUTION]: The inclusion of code snippets facilitating the loading of remote models with execution privileges (trust_remote_code=True) provides a pathway for remote code execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a retrieval-augmented generation (RAG) workflow that ingests potentially untrusted external data.
  • Ingestion points: The workflow in SKILL.md and references/chunking-strategies.md processes raw document content (raw_docs, document_text) for indexing and retrieval.
  • Boundary markers: The code examples for building retrieval pipelines do not demonstrate the use of delimiters or protective instructions to prevent the LLM from following commands embedded within retrieved documents.
  • Capability inventory: The skill utilizes tools for network communication (OpenAI, Cohere APIs) and database operations (Pinecone, Qdrant, Weaviate), creating a risk that injected instructions could trigger unauthorized actions.
  • Sanitization: No sanitization or filtering logic is present in the retrieval examples to clean or validate external content before it is used in prompt context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 09:19 PM
Security Audit — agent-trust-hub — rag-architect