qdrant-vector-search

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to install standard, well-known libraries including qdrant-client, sentence-transformers, langchain-community, and llama-index-vector-stores-qdrant via official package registries.
  • [COMMAND_EXECUTION]: Includes instructions for running official Qdrant Docker containers and managing the local Docker daemon using sudo systemctl within the troubleshooting guide. These are standard administrative tasks for local development environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data for RAG (Retrieval-Augmented Generation) pipelines, which represents a potential attack surface.
  • Ingestion points: Document data is ingested via the client.upsert method in SKILL.md and references/rag-integration.md.
  • Boundary markers: The provided examples do not demonstrate the use of specific boundary markers or 'ignore' instructions for the retrieved content.
  • Capability inventory: The skill uses client.search and client.query_points to retrieve data that is then interpolated into LLM prompts.
  • Sanitization: No explicit sanitization or filtering of the retrieved document content is shown in the integration examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — qdrant-vector-search