faiss

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTION
Full Analysis
  • Dynamic Execution (MEDIUM): The LangChain integration example in SKILL.md includes the parameter allow_dangerous_deserialization=True. This flag allows the library to use Python's pickle module to load data, which is a known security risk. If a user loads a FAISS index from an untrusted source with this setting enabled, it could result in arbitrary code execution on the host system.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 06:04 PM