vector-store

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The server.py implementation includes a /shutdown API endpoint that triggers process termination via os._exit(0). This allows any entity with network access to the service to terminate the vector store process.\n- [PROMPT_INJECTION]: The skill serves as a vector database, creating a surface for indirect prompt injection if the stored identifiers (ids) are retrieved and used in LLM prompts without proper sanitization.\n
  • Ingestion points: User-provided string IDs in the /index endpoint of server.py.\n
  • Boundary markers: No delimiters or instructions to ignore embedded content are present in the data handling logic.\n
  • Capability inventory: The skill provides similarity search and data retrieval over indexed vectors.\n
  • Sanitization: The IDs are stored and returned exactly as provided without validation or escaping.\n- [DATA_EXFILTRATION]: The run.sh script is configured to source a .env file from a wide parent directory path (../../../.env). This pattern may inadvertently load sensitive environment variables from a higher-level project root into the active service context.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — vector-store