pinecone

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational content and integration guides for Pinecone, a well-known managed vector database. The instructions follow industry best practices for RAG (Retrieval-Augmented Generation) systems.
  • [INDIRECT_PROMPT_INJECTION]: The skill inherently handles external data retrieved from a vector database, which presents a surface for indirect prompt injection. However, the 'Agent operating procedure' and 'Integrity rules' sections provide guidelines for the agent to validate results and ensure answers come from retrieved text, which are standard mitigations.
  • [CREDENTIALS_UNSAFE]: The code examples use standard placeholders for API keys (e.g., 'your-api-key', 'your-key'). These are non-functional strings and do not represent a credential exposure risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — pinecone