rag-agent-builder
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements RAG patterns that ingest untrusted external data (retrieved context) and user-supplied queries, which are then interpolated directly into prompts. This creates an attack surface where malicious instructions in the documents could influence the agent's behavior.
- Ingestion points: External data enters the system context via the
contextanddocumentsvariables inexamples/basic_rag.pyandexamples/agentic_rag.py. - Boundary markers: The prompt templates in the examples (e.g.,
generate_answerandevaluate_retrieved_docs) do not utilize delimiters or specific instructions to disregard embedded commands in the context data. - Capability inventory: The system leverages the untrusted context to perform generation tasks and agentic reasoning decisions, such as those found in the
AgenticRAG.decide_retrievalmethod. - Sanitization: The implementation lacks evidence of text sanitization, validation, or escaping for the external content before it is processed by the model.
Audit Metadata