llamaindex
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is primarily focused on building RAG pipelines, which involves ingesting data from external and potentially untrusted sources such as web pages, GitHub repositories, and local directories. This architecture creates a significant surface for indirect prompt injection attacks.
- Ingestion Points: The skill utilizes various loaders such as
SimpleWebPageReader,BeautifulSoupWebReader,GithubRepositoryReader,DatabaseReader, andJSONReaderto bring external content into the LLM context (found inSKILL.mdandreferences/data_connectors.md). - Boundary Markers: The documentation provides examples of
PromptTemplateconfigurations (e.g., inSKILL.mdandreferences/query_engines.md) that include instructions like "Answer the question based only on the context." While these provide a basic instruction-based boundary, they do not programmatically prevent an LLM from obeying instructions hidden within the data. - Capability Inventory: The agent has the capability to perform network requests for data retrieval, access the local file system, query databases, and interact with external LLM APIs (OpenAI, Anthropic).
- Sanitization: The provided code snippets do not implement explicit sanitization, filtering, or validation of the ingested content before it is interpolated into the prompt templates.
- [CREDENTIALS_UNSAFE]: The skill's documentation and reference files include code examples that demonstrate how to connect to databases and cloud vector stores using sensitive credentials.
- Evidence:
SKILL.mdcontains examples forDatabaseReaderusing a URI string (postgresql://user:pass@localhost/db) andPineconeVectorStoreusing an API key (api_key="your-key").references/data_connectors.mdalso showsNotionPageReaderusing an integration token. These are correctly implemented as placeholders for user-provided secrets and do not represent actual hardcoded credentials.
Audit Metadata