skills/zvec-ai/zvec-agent-skills/zvec/Gen Agent Trust Hub

zvec

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation instructs users to install standard packages including 'zvec', '@zvec/zvec', 'openai', 'dashscope', 'dashtext', and 'sentence-transformers' from official registries. It also references pre-trained models from established platforms like HuggingFace and Modelscope.\n- [INDIRECT_PROMPT_INJECTION]: The skill facilitates building Retrieval-Augmented Generation (RAG) systems which process untrusted document content.\n
  • Ingestion points: External content is ingested into document fields as seen in rag-system/python.md and rag-system/typescript.md.\n
  • Boundary markers: Examples do not demonstrate the use of delimiters or instructions to ignore embedded commands within the processed data.\n
  • Capability inventory: The skill utilizes database persistence and network API calls to AI providers (OpenAI, Jina, Dashscope).\n
  • Sanitization: No explicit sanitization or validation of the ingested document content is described in the provided examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:01 PM
Security Audit — agent-trust-hub — zvec