software-search
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes systems that process untrusted user-supplied search queries, which is a potential surface for prompt injection.
- Ingestion points: User-provided search strings are ingested for retrieval, autocomplete, and query classification (SKILL.md, Scenario S3).
- Boundary markers: The skill includes explicit instructions to use allowlisted fields and avoid passing raw JSON filters to the backend (SKILL.md, Vector Search API Pattern).
- Capability inventory: The skill provides architectural design guidance and contains no executable scripts (Python, Node.js, or Shell) with file-write or network-write capabilities.
- Sanitization: Recommends strict input validation and sanitization before embedding generation or query construction.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and repositories from well-known technology providers.
- Fetches guidelines and references from primary documentation for PostgreSQL, Elasticsearch, OpenSearch, and Algolia in data/sources.json.
- References the official pgvector repository on GitHub for vector search functionality.
Audit Metadata