chroma
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate technical documentation and code samples for interacting with ChromaDB. Code examples use appropriate placeholders for API keys and demonstrate standard library usage. No evidence of credential theft, unauthorized data access, or malicious commands was found.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for ingesting and retrieving untrusted text documents within a vector database. This architecture is a known surface for indirect prompt injection in RAG pipelines. However, as this is the primary intended purpose of the database integration, and no specific exploits or safety bypasses were included, the risk is categorized as safe within the context of this skill's use case.
Audit Metadata