pgvector-search

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides architecture and code for implementing hybrid search (combining semantic vector search and keyword-based BM25 search) using SQLAlchemy and PGVector.
  • [SAFE]: Database interactions in the provided Python templates use SQLAlchemy's ORM and expression language, which inherently uses parameter binding to protect against SQL injection.
  • [SAFE]: For full-text search, the implementation uses the plainto_tsquery function, which is a recommended practice to safely convert user-supplied strings into valid tsquery objects, preventing syntax errors or potential injection attacks.
  • [SAFE]: External references are limited to official technology documentation (PostgreSQL, PGVector), well-known services (Voyage AI), and reputable academic sources for the algorithms used (RRF, HNSW).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 10:02 AM
Security Audit — agent-trust-hub — pgvector-search