rag-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external document data, which is an inherent surface for indirect prompt injection. The instructions include defensive measures such as explicit system prompts that treat retrieved passages as data and ignore embedded instructions, alongside verification steps for citations.
  • Ingestion points: Documents processed by chunking logic in SKILL.md and contextual retrieval in ADVANCED_RETRIEVAL.md.
  • Boundary markers: Includes recommended system prompt instructions specifically designed to delimit data and ignore instructions.
  • Capability inventory: Tools include Bash, psql, and file system read/write access.
  • Sanitization: Recommends reranking to improve precision and mechanical verification of grounding and citations.
  • [COMMAND_EXECUTION]: Provides SQL and Python templates for data management and indexing. The SQL examples correctly prioritize security boundaries by implementing Row Level Security (RLS) to ensure tenant isolation.
  • [EXTERNAL_DOWNLOADS]: Mentions standard libraries and models such as sentence-transformers and pgvector. These are well-known and reputable resources within the industry.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — rag-expert