vector-specialist

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for 'Query Expansion' and 'Query Understanding' that interpolate raw user input directly into LLM prompts, creating a surface for injection attacks.
  • Ingestion points: The query parameter in the expand_query function (found in references/patterns.md) and the understand_query function (found in references/sharp_edges.md).
  • Boundary markers: No specific delimiters (like XML tags or triple quotes) or 'ignore' instructions are used to separate the user-provided query from the prompt instructions.
  • Capability inventory: The functions utilize llm.complete to generate query variations or extract entities, which could be manipulated to execute unintended instructions if the input is adversarial.
  • Sanitization: The code snippets do not include logic for sanitizing, escaping, or validating the query string before it is interpolated into the f-string prompt templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:54 PM
Security Audit — agent-trust-hub — vector-specialist