customgpt-rag
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOWPROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill facilitates the ingestion of external data from a knowledge base, which can serve as a vector for indirect prompt injection. Ingestion points: Data enters the agent's context through the mcp__customgpt__send_message function. Boundary markers: The provided patterns do not include delimiters or instructions to treat the RAG output as untrusted data. Capability inventory: Based on the description, the skill is limited to information retrieval and document synthesis, which restricts potential impact to internal reasoning changes. Sanitization: There is no evidence of sanitization or filtering of the retrieved content.
Audit Metadata