skills/itamaker/skills/ragcheck/Gen Agent Trust Hub

ragcheck

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data in the form of JSON files for evaluation tasks. This creates a surface for indirect prompt injection where malicious input could influence tool output or agent behavior.\n
  • Ingestion points: The skill reads query relevance judgments (qrels.json), retrieval results (run.json), and RAG evaluation records (judge.json) as specified in SKILL.md.\n
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are present in the prompt patterns or command descriptions.\n
  • Capability inventory: The agent is instructed to execute shell commands such as go run, go build, and the ragcheck binary as described in SKILL.md and references/REFERENCE.md.\n
  • Sanitization: No sanitization or validation of the input file content is described in the provided documentation.\n- [DYNAMIC_EXECUTION]: The skill instructions involve compiling and executing the tool's Go source code at runtime.\n
  • Evidence: SKILL.md describes building the tool using go build -o ragcheck . and running subcommands via go run . ...\n- [EXTERNAL_DOWNLOADS]: The skill suggests downloading the CLI tool from the author's GitHub repository or via a Homebrew tap. These resources are owned by the vendor 'itamaker'.\n
  • Evidence: SKILL.md mentions brew install itamaker/tap/ragcheck and github.com/itamaker/ragcheck-skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 10:09 AM
Security Audit — agent-trust-hub — ragcheck