pgvector-search
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides architecture and code for implementing hybrid search (combining semantic vector search and keyword-based BM25 search) using SQLAlchemy and PGVector.
- [SAFE]: Database interactions in the provided Python templates use SQLAlchemy's ORM and expression language, which inherently uses parameter binding to protect against SQL injection.
- [SAFE]: For full-text search, the implementation uses the
plainto_tsqueryfunction, which is a recommended practice to safely convert user-supplied strings into valid tsquery objects, preventing syntax errors or potential injection attacks. - [SAFE]: External references are limited to official technology documentation (PostgreSQL, PGVector), well-known services (Voyage AI), and reputable academic sources for the algorithms used (RRF, HNSW).
Audit Metadata