rag-architect
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
LateChunkerclass inreferences/chunking-strategies.mduses thetrust_remote_code=Trueparameter within thetransformerslibrary initialization. This configuration enables the execution of arbitrary Python code provided by the model repository during the loading process, which represents a potential supply-chain vulnerability. - [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by ingesting and interpolating untrusted external data into LLM prompts without sanitization or boundary markers across its evaluation and retrieval optimization modules.
- Ingestion points: Specifically found in
references/rag-evaluation.md(evaluate_with_llmfunction) andreferences/retrieval-optimization.md(expand_query,rewrite_query_for_retrieval, andcompress_retrieved_contextfunctions) which process user queries, chat history, and document content. - Boundary markers: Absent. The implementation utilizes direct string interpolation (f-strings) to embed external data into system and user prompts without delimiters or instructions to ignore embedded commands.
- Capability inventory: The skill possesses the capability to interact with external LLM APIs (
openai,cohere) using the processed data, which could lead to altered agent behavior or data manipulation if the source content is malicious. - Sanitization: Absent. There is no evidence of content validation, escaping, or filtering for instructions before interpolation into prompt templates.
Audit Metadata