embedding
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runinembed.pyandbackfill_multimodal.pyto manage local Docker containers (embry-embedding,embry-embedding-mm). This is used for service orchestration and health recovery (restarting containers on failure). - [EXTERNAL_DOWNLOADS]: The skill fetches dependencies from vendor-owned repositories during installation, specifically
graph-memoryandscillmfromgithub.com/grahama1970. These are used for Knowledge Graph operations and LLM proxying. - [INDIRECT_PROMPT_INJECTION]: The
edge-verifierskill processes untrusted source text through an LLM to determine relationships for the Knowledge Graph. While it uses a system prompt to define output format, it lacks explicit sanitization for the ingested content, creating a surface for indirect injection. - Ingestion points:
verify_edges.pyvia the--textargument. - Boundary markers: System prompt defined within the verification loop.
- Capability inventory: Performs
db.aql.executeto UPSERT verified edges into ArangoDB. - Sanitization: Relies on system prompt and JSON parsing; no specific content filtering for the source text.
- [CREDENTIALS_UNSAFE]: The file
edge-verifier/verify_edges.pycontains a hardcoded default valuesk-dev-proxy-123for theSCILLM_PROXY_KEY. While clearly intended as a local development placeholder for thelocalhost:4001proxy, it matches a credential pattern.
Audit Metadata