ai-rag

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: CRITICALINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for processing external document data, which represents a vulnerability surface for indirect prompt injection attacks. * Ingestion points: External document data is ingested for evaluation in scripts/exact_search_baseline.py and scripts/hybrid_rrf_demo.py. * Boundary markers: Grounding templates in assets/context/template-grounding.md implement explicit delimiters such as <CONTEXT_BLOCK> and <USER_QUERY>. * Capability inventory: The provided scripts are limited to local vector computation and file processing with no high-risk capabilities like shell execution or arbitrary network control. * Sanitization: The skill recommends proactive controls including PII redaction and LLM-based faithfulness checks.
  • [EXTERNAL_DOWNLOADS]: The script scripts/check_sources.py performs network HEAD requests to validate URLs in the source catalog. These requests target well-known research repositories and official documentation sites.
  • [SAFE]: No malicious logic, obfuscation, or persistence mechanisms were found. Automated scanner hits for trulens.org and sources.json were evaluated and determined to be false positives; TruLens is a legitimate observability tool and the JSON file is a standard reference catalog.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 23, 2026, 06:07 PM
Security Audit — agent-trust-hub — ai-rag