faiss

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill includes instructions that enable the deserialization of potentially untrusted data. * Evidence: In SKILL.md, the LangChain integration section demonstrates loading a local index using allow_dangerous_deserialization=True. This setting permits the use of Python's pickle module, which is inherently unsafe and can lead to arbitrary code execution if the index file originates from an untrusted source.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content, establishing a surface for indirect prompt injection. * Ingestion points: The skill ingests external docs and user-provided query strings in the LangChain and LlamaIndex examples within SKILL.md. * Boundary markers: There are no specific instructions for using delimiters or boundary markers to separate untrusted data from the agent's primary instructions. * Capability inventory: The skill performs file I/O (saving and loading indices) and vector search operations across SKILL.md and references/index_types.md. * Sanitization: The provided code snippets do not include logic for sanitizing or validating external input before it is processed by the search engine.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — faiss