embedding

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in embed.py and backfill_multimodal.py to manage local Docker containers (embry-embedding, embry-embedding-mm). This is used for service orchestration and health recovery (restarting containers on failure).
  • [EXTERNAL_DOWNLOADS]: The skill fetches dependencies from vendor-owned repositories during installation, specifically graph-memory and scillm from github.com/grahama1970. These are used for Knowledge Graph operations and LLM proxying.
  • [INDIRECT_PROMPT_INJECTION]: The edge-verifier skill processes untrusted source text through an LLM to determine relationships for the Knowledge Graph. While it uses a system prompt to define output format, it lacks explicit sanitization for the ingested content, creating a surface for indirect injection.
  • Ingestion points: verify_edges.py via the --text argument.
  • Boundary markers: System prompt defined within the verification loop.
  • Capability inventory: Performs db.aql.execute to UPSERT verified edges into ArangoDB.
  • Sanitization: Relies on system prompt and JSON parsing; no specific content filtering for the source text.
  • [CREDENTIALS_UNSAFE]: The file edge-verifier/verify_edges.py contains a hardcoded default value sk-dev-proxy-123 for the SCILLM_PROXY_KEY. While clearly intended as a local development placeholder for the localhost:4001 proxy, it matches a credential pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:48 AM
Security Audit — agent-trust-hub — embedding