faiss
Warn
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill includes instructions that enable the deserialization of potentially untrusted data. * Evidence: In
SKILL.md, the LangChain integration section demonstrates loading a local index usingallow_dangerous_deserialization=True. This setting permits the use of Python'spicklemodule, which is inherently unsafe and can lead to arbitrary code execution if the index file originates from an untrusted source. - [INDIRECT_PROMPT_INJECTION]: The skill processes external content, establishing a surface for indirect prompt injection. * Ingestion points: The skill ingests external
docsand user-providedquerystrings in the LangChain and LlamaIndex examples withinSKILL.md. * Boundary markers: There are no specific instructions for using delimiters or boundary markers to separate untrusted data from the agent's primary instructions. * Capability inventory: The skill performs file I/O (saving and loading indices) and vector search operations acrossSKILL.mdandreferences/index_types.md. * Sanitization: The provided code snippets do not include logic for sanitizing or validating external input before it is processed by the search engine.
Audit Metadata