rag
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill manages the risks associated with processing external, untrusted document corpora by implementing a rigorous grounding contract. Ingestion points: Document chunks are ingested and formatted into the prompt context in
SKILL.mdandreferences/pipeline.md. Boundary markers: The instructions mandate strict isolation of data using specific tags and system-level constraints to ensure the agent only uses the provided context. Capability inventory: The skill uses network-based APIs for reranking and grounding but does not execute arbitrary code or write to the filesystem based on external input. Sanitization: The approach relies on an explicit refusal policy and citation requirements to mitigate potential injection attempts within the corpus.
Audit Metadata