vector-db
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions and recipes for querying vector databases (pgvector, Qdrant, Weaviate, Pinecone) using user-provided filters and semantic search. This creates a surface for indirect prompt injection if the data retrieved from the vector store contains malicious instructions intended to influence the agent's behavior.
- Ingestion points: Similarity search results and metadata filters as described in
SKILL.mdandreferences/engines.md. - Boundary markers: The skill does not provide specific instructions for using delimiters or boundary markers to isolate data retrieved from the database from the agent's instructions.
- Capability inventory: The agent interacts with external database engines using SQL and Python client libraries and can execute local scripts.
- Sanitization: There is no explicit mention of sanitizing or validating the content retrieved from vector databases before processing it.
- [COMMAND_EXECUTION]: The skill includes a local utility script,
scripts/verify.sh, and instructs the agent to run it to lint and verify vector store artifacts. - The script uses standard shell utilities such as
findandgrepto perform heuristic analysis on local files. - Evidence:
SKILL.mdcontains the instruction: "Validate a produced index DDL / collection schema withscripts/verify.sh <artifact-file>."
Audit Metadata