RAG Production Engineering

Security checks across malware telemetry and agentic risk

Overview

This is a markdown-only RAG engineering guidance skill with no executable code or hidden runtime access.

Reasonable to install as a RAG methodology reference. Verify the install slug before using the README command, and separately apply privacy, retention, access-control, and compliance safeguards when using the guidance to build systems that index private documents.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill defines very broad natural-language triggers such as "Set up a RAG system," "Optimize retrieval," and "Review my RAG architecture," which overlap heavily with ordinary user requests in a general AI environment. This can cause unintended invocation or privilege/behavior switching when a user is merely asking for advice, increasing the risk that the skill activates unexpectedly and applies specialized instructions outside the user's intended scope.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal