vector-specialist
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for 'Query Expansion' and 'Query Understanding' that interpolate raw user input directly into LLM prompts, creating a surface for injection attacks.
- Ingestion points: The
queryparameter in theexpand_queryfunction (found inreferences/patterns.md) and theunderstand_queryfunction (found inreferences/sharp_edges.md). - Boundary markers: No specific delimiters (like XML tags or triple quotes) or 'ignore' instructions are used to separate the user-provided query from the prompt instructions.
- Capability inventory: The functions utilize
llm.completeto generate query variations or extract entities, which could be manipulated to execute unintended instructions if the input is adversarial. - Sanitization: The code snippets do not include logic for sanitizing, escaping, or validating the
querystring before it is interpolated into the f-string prompt templates.
Audit Metadata