chroma
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed for Retrieval-Augmented Generation (RAG) tasks, which involves ingesting and processing external data, naturally presenting an indirect prompt injection surface.
- Ingestion points: Document and metadata ingestion occurs through
collection.addand various framework-specific loaders (e.g.,Chroma.from_documentsin LangChain) as shown inSKILL.mdandreferences/integration.md. - Boundary markers: The provided examples do not demonstrate the use of specific boundary markers or instructions to isolate retrieved content from agent commands.
- Capability inventory: The skill demonstrates capabilities for local file system writes (for database persistence at
./chroma_db) and network operations (for communication with embedding providers like OpenAI and HuggingFace, or remote Chroma servers). - Sanitization: Consistent with documentation of basic API usage, no explicit input validation or sanitization logic is present in the examples.
- [EXTERNAL_DOWNLOADS]: The skill references standard, well-known packages from official registries for its core functionality and integrations.
- Python packages:
chromadb,sentence-transformers,langchain-chroma,langchain-openai,llama-index-vector-stores-chroma, andllama-index-core. - Node.js packages:
chromadband@chroma-core/default-embed.
Audit Metadata