agent

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the user in building an AI agent that utilizes Retrieval-Augmented Generation (RAG) and message history. This architecture naturally ingests untrusted external data (documents and user messages) which could contain adversarial instructions. \n
  • Ingestion points: Processes external documents for vector search and user-provided messages for chat threads as described in SKILL.md. \n
  • Capability inventory: The agent is designed to support tool-calls and vector search, providing potential actions for an injection to trigger. \n
  • Boundary markers: The instructions do not explicitly detail the use of delimiters or system-level instructions to ignore data-embedded commands. \n
  • Sanitization: The guide does not specify methods for sanitizing or escaping the retrieved content before it is processed by the LLM.\n- [EXTERNAL_DOWNLOADS]: The skill recommends the installation of the @convex-dev/agent package. This resource is provided by the vendor to facilitate AI agent integration within their ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 02:52 AM
Security Audit — agent-trust-hub — agent