rag-wrapper
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval of external data from a Qdrant database and inserts it into the prompt of a target agent, which is a standard pattern that introduces an indirect prompt injection surface.
- Ingestion points: Data is ingested through the
qdrant-findtool and stored in thecontentvariable within theEnriched Prompt Templatein SKILL.md. - Boundary markers: The skill uses markdown headers (e.g.,
## From Qdrant) and horizontal separators (---) to delimit the retrieved context from the task, but does not provide explicit instructions to the downstream agent to treat the retrieved content as untrusted data. - Capability inventory: The skill utilizes data retrieval (
qdrant-find), data storage (qdrant-store), and agent delegation (Tasktool) in SKILL.md. - Sanitization: No sanitization, filtering, or validation of the content retrieved from the database is performed before it is presented to the target agent.
Audit Metadata