rag-architect

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation file references/chunking-strategies.md includes a code snippet for LateChunker that uses AutoModel.from_pretrained(model_name, trust_remote_code=True). Enabling trust_remote_code allows the library to download and execute arbitrary Python code contained within the model's repository.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download pre-trained machine learning models from external repositories like Hugging Face and to interface with various third-party APIs (OpenAI, Cohere, Voyage AI, etc.).
  • [DATA_EXFILTRATION]: The workflow involves reading local documents and sending their content to external cloud-based APIs for processing, which represents a potential path for data exposure.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points: External documents are processed in SKILL.md and references/chunking-strategies.md. Boundary markers: None identified; document content is concatenated directly into prompts via string joining. Capability inventory: The skill uses network APIs (OpenAI, Cohere), vector database persistence, and file processing. Sanitization: No evidence of content filtering or safety instructions to ignore embedded commands.
  • [SAFE]: The skill follows security best practices by using placeholders for API keys and suggesting the use of environment variables for secret management.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — rag-architect