AgentDB Vector Search
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a Retrieval-Augmented Generation (RAG) pattern, creating a surface for indirect prompt injection where untrusted data from the vector database is interpolated into the model's prompt.\n
- Ingestion points: Documents stored via
db.storeWithEmbedding,db.batchStore, and retrieved context in theragQueryfunction.\n - Boundary markers: The prompt template in
SKILL.mduses basic labels (Context:,Question:) but lacks robust delimiters or explicit instructions to the model to ignore potential commands within the retrieved text.\n - Capability inventory: The skill utilizes the
agentic-flowlibrary andagentdbCLI for database operations and document management.\n - Sanitization: The provided examples do not demonstrate sanitization or escaping of retrieved content before it is added to the generating prompt.\n- [EXTERNAL_DOWNLOADS]: The skill documentation references
npx agentdb@latestand theagentic-flowlibrary. These are vendor-controlled resources from 'ruvnet' and are used for the intended purpose of database management.\n- [COMMAND_EXECUTION]: The skill provides instructions for executing the AgentDB CLI and configuring an MCP server (npx agentdb@latest mcp) to integrate with the agent environment.
Audit Metadata