AgentDB Vector Search

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a Retrieval-Augmented Generation (RAG) pattern, creating a surface for indirect prompt injection where untrusted data from the vector database is interpolated into the model's prompt.\n
  • Ingestion points: Documents stored via db.storeWithEmbedding, db.batchStore, and retrieved context in the ragQuery function.\n
  • Boundary markers: The prompt template in SKILL.md uses basic labels (Context:, Question:) but lacks robust delimiters or explicit instructions to the model to ignore potential commands within the retrieved text.\n
  • Capability inventory: The skill utilizes the agentic-flow library and agentdb CLI for database operations and document management.\n
  • Sanitization: The provided examples do not demonstrate sanitization or escaping of retrieved content before it is added to the generating prompt.\n- [EXTERNAL_DOWNLOADS]: The skill documentation references npx agentdb@latest and the agentic-flow library. These are vendor-controlled resources from 'ruvnet' and are used for the intended purpose of database management.\n- [COMMAND_EXECUTION]: The skill provides instructions for executing the AgentDB CLI and configuring an MCP server (npx agentdb@latest mcp) to integrate with the agent environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — AgentDB Vector Search