rag-implementer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes architecture patterns for ingesting external data into Large Language Model prompts. While this represents a natural attack surface for indirect prompt injection (where malicious content in documents could influence agent behavior), the skill explicitly recommends security best practices to mitigate these risks, including sensitive data filtering, PII protection, and human review protocols.
- [COMMAND_EXECUTION]: The skill provides code templates and implementation logic for document processing and vector database interactions. These are documented as educational references for the user to implement and do not involve the agent executing unauthorized or high-privilege shell commands.
Audit Metadata