chroma

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed for Retrieval-Augmented Generation (RAG) tasks, which involves ingesting and processing external data, naturally presenting an indirect prompt injection surface.
  • Ingestion points: Document and metadata ingestion occurs through collection.add and various framework-specific loaders (e.g., Chroma.from_documents in LangChain) as shown in SKILL.md and references/integration.md.
  • Boundary markers: The provided examples do not demonstrate the use of specific boundary markers or instructions to isolate retrieved content from agent commands.
  • Capability inventory: The skill demonstrates capabilities for local file system writes (for database persistence at ./chroma_db) and network operations (for communication with embedding providers like OpenAI and HuggingFace, or remote Chroma servers).
  • Sanitization: Consistent with documentation of basic API usage, no explicit input validation or sanitization logic is present in the examples.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, well-known packages from official registries for its core functionality and integrations.
  • Python packages: chromadb, sentence-transformers, langchain-chroma, langchain-openai, llama-index-vector-stores-chroma, and llama-index-core.
  • Node.js packages: chromadb and @chroma-core/default-embed.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — chroma