software-search

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes systems that process untrusted user-supplied search queries, which is a potential surface for prompt injection.
  • Ingestion points: User-provided search strings are ingested for retrieval, autocomplete, and query classification (SKILL.md, Scenario S3).
  • Boundary markers: The skill includes explicit instructions to use allowlisted fields and avoid passing raw JSON filters to the backend (SKILL.md, Vector Search API Pattern).
  • Capability inventory: The skill provides architectural design guidance and contains no executable scripts (Python, Node.js, or Shell) with file-write or network-write capabilities.
  • Sanitization: Recommends strict input validation and sanitization before embedding generation or query construction.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and repositories from well-known technology providers.
  • Fetches guidelines and references from primary documentation for PostgreSQL, Elasticsearch, OpenSearch, and Algolia in data/sources.json.
  • References the official pgvector repository on GitHub for vector search functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — software-search