rag-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external document data, which is an inherent surface for indirect prompt injection. The instructions include defensive measures such as explicit system prompts that treat retrieved passages as data and ignore embedded instructions, alongside verification steps for citations.
- Ingestion points: Documents processed by chunking logic in SKILL.md and contextual retrieval in ADVANCED_RETRIEVAL.md.
- Boundary markers: Includes recommended system prompt instructions specifically designed to delimit data and ignore instructions.
- Capability inventory: Tools include Bash, psql, and file system read/write access.
- Sanitization: Recommends reranking to improve precision and mechanical verification of grounding and citations.
- [COMMAND_EXECUTION]: Provides SQL and Python templates for data management and indexing. The SQL examples correctly prioritize security boundaries by implementing Row Level Security (RLS) to ensure tenant isolation.
- [EXTERNAL_DOWNLOADS]: Mentions standard libraries and models such as
sentence-transformersandpgvector. These are well-known and reputable resources within the industry.
Audit Metadata