vector-db

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions and recipes for querying vector databases (pgvector, Qdrant, Weaviate, Pinecone) using user-provided filters and semantic search. This creates a surface for indirect prompt injection if the data retrieved from the vector store contains malicious instructions intended to influence the agent's behavior.
  • Ingestion points: Similarity search results and metadata filters as described in SKILL.md and references/engines.md.
  • Boundary markers: The skill does not provide specific instructions for using delimiters or boundary markers to isolate data retrieved from the database from the agent's instructions.
  • Capability inventory: The agent interacts with external database engines using SQL and Python client libraries and can execute local scripts.
  • Sanitization: There is no explicit mention of sanitizing or validating the content retrieved from vector databases before processing it.
  • [COMMAND_EXECUTION]: The skill includes a local utility script, scripts/verify.sh, and instructs the agent to run it to lint and verify vector store artifacts.
  • The script uses standard shell utilities such as find and grep to perform heuristic analysis on local files.
  • Evidence: SKILL.md contains the instruction: "Validate a produced index DDL / collection schema with scripts/verify.sh <artifact-file>."
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — vector-db