ai-rag
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external document data, which represents a vulnerability surface for indirect prompt injection attacks. * Ingestion points: External document data is ingested for evaluation in scripts/exact_search_baseline.py and scripts/hybrid_rrf_demo.py. * Boundary markers: Grounding templates in assets/context/template-grounding.md implement explicit delimiters such as <CONTEXT_BLOCK> and <USER_QUERY>. * Capability inventory: The provided scripts are limited to local vector computation and file processing with no high-risk capabilities like shell execution or arbitrary network control. * Sanitization: The skill recommends proactive controls including PII redaction and LLM-based faithfulness checks.
- [EXTERNAL_DOWNLOADS]: The script scripts/check_sources.py performs network HEAD requests to validate URLs in the source catalog. These requests target well-known research repositories and official documentation sites.
- [SAFE]: No malicious logic, obfuscation, or persistence mechanisms were found. Automated scanner hits for trulens.org and sources.json were evaluated and determined to be false positives; TruLens is a legitimate observability tool and the JSON file is a standard reference catalog.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata