rag-architect

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The LateChunker class in references/chunking-strategies.md uses the trust_remote_code=True parameter within the transformers library initialization. This configuration enables the execution of arbitrary Python code provided by the model repository during the loading process, which represents a potential supply-chain vulnerability.
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface by ingesting and interpolating untrusted external data into LLM prompts without sanitization or boundary markers across its evaluation and retrieval optimization modules.
  • Ingestion points: Specifically found in references/rag-evaluation.md (evaluate_with_llm function) and references/retrieval-optimization.md (expand_query, rewrite_query_for_retrieval, and compress_retrieved_context functions) which process user queries, chat history, and document content.
  • Boundary markers: Absent. The implementation utilizes direct string interpolation (f-strings) to embed external data into system and user prompts without delimiters or instructions to ignore embedded commands.
  • Capability inventory: The skill possesses the capability to interact with external LLM APIs (openai, cohere) using the processed data, which could lead to altered agent behavior or data manipulation if the source content is malicious.
  • Sanitization: Absent. There is no evidence of content validation, escaping, or filtering for instructions before interpolation into prompt templates.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — rag-architect