vector-store
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The
server.pyimplementation includes a/shutdownAPI endpoint that triggers process termination viaos._exit(0). This allows any entity with network access to the service to terminate the vector store process.\n- [PROMPT_INJECTION]: The skill serves as a vector database, creating a surface for indirect prompt injection if the stored identifiers (ids) are retrieved and used in LLM prompts without proper sanitization.\n - Ingestion points: User-provided string IDs in the
/indexendpoint ofserver.py.\n - Boundary markers: No delimiters or instructions to ignore embedded content are present in the data handling logic.\n
- Capability inventory: The skill provides similarity search and data retrieval over indexed vectors.\n
- Sanitization: The IDs are stored and returned exactly as provided without validation or escaping.\n- [DATA_EXFILTRATION]: The
run.shscript is configured to source a.envfile from a wide parent directory path (../../../.env). This pattern may inadvertently load sensitive environment variables from a higher-level project root into the active service context.
Audit Metadata