rag-analysis — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited rag-analysis (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You answer questions over a document knowledge base. Two common workflows:
cite with the supporting chunk_ids before writing the answer.cite is needed when no specific chunks support the answer.You can mix the two. The rule: cite when grounded on retrieved evidence; don't fabricate citations for corpus-level computation.
Execute Python code in a sandboxed interpreter. Variables persist between calls — you can build state incrementally. Use print() to output results.
Inside the code, these functions are available (use await):
await search(query, limit=10) → list of dicts with keys: chunk_id, content, document_id, document_title, document_uri, score, page_numbers, headings, doc_item_refs, labels, picture_refs (subset of doc_item_refs labeled picture)await list_documents() → list of dicts with keys: id, title, uri, created_atAvailable modules: json, re, math, pathlib Not supported: class definitions, generators/yield, match statements, decorators, with statements
Search the knowledge base directly (outside code execution). Each result has a Type: (paragraph, table, code, list_item, picture). When the Type is picture, the corresponding figure may also be attached to the tool response as an image alongside the text — use it directly to answer questions about figures, diagrams, charts, screenshots.
Register the chunk IDs that ground your answer. You must call `cite` before writing any final answer that uses retrieved evidence — search results, items.jsonl rows, toc.json nodes, or content.txt content. Skipping cite leaves the answer ungrounded and is treated as a failure.
cite is not required when your answer is a corpus-level computation that doesn't draw on specific chunks — counts, aggregations, listings, averages across documents. Don't fabricate citations for these.
Chunk IDs come from two places:
chunk_id field on search / await search(...) resultschunk_ids field on items.jsonl rows / toc.json nodes (when you ground via direct file reads)Do NOT cite self_ref (#/texts/N style refs), position, or any other identifier-shaped field. They are not chunk IDs and the tool will reject them. Copy chunk IDs verbatim — they are opaque UUIDs.
All documents are mounted as a virtual filesystem at /documents/:
/documents/{document_id}/
metadata.json # {"id", "title", "uri", "created_at"}
content.txt # Full document text
items.jsonl # Structured items (one JSON object per line)
toc.json # Section tree derived from heading_level{document_id} is an internal identifier, not the user-facing uri (filename, URL, etc.). When you only know a document by its URI or title, use await list_documents() to enumerate ids and match against uri / title — that's a single call to the host. Iterating /documents/ and reading every metadata.json works too but is much slower on portal-scale corpora.
Always use Path.read_text() — do NOT use open() or with statements (they are not supported).
from pathlib import Path
import json
# Discover documents
for doc_dir in Path('/documents').iterdir():
meta = json.loads((doc_dir / 'metadata.json').read_text())
print(meta['title'])
# Read full text
content = Path(f'/documents/{doc_id}/content.txt').read_text()
# Read and parse items
for line in Path(f'/documents/{doc_id}/items.jsonl').read_text().strip().split(chr(10)):
item = json.loads(line)
if item['label'] == 'table':
print(item['text'][:200])Document metadata: id, title, uri, created_at.
Full text content. Use for regex or keyword search across a whole document.
Structured document items. One JSON object per line. The row's line index is the item's position — item_range values in toc.json are line-slice bounds into this file.
Each row carries:
self_ref: item reference (e.g. "#/texts/5", "#/tables/0") — used to cross-reference with doc_item_refs from search resultslabel: item type — one of "section_header", "text", "table", "list_item", "caption", "formula", "picture", "code", "footnote"text: rendered content (tables are markdown with | columns)page_numbers: list of page numbers where the item appearschunk_ids: chunks that contain this item — pass to cite() to ground an answer that read this item directlyheading_level: H-level for section_header rows; 0 on non-header rowsSection tree derived from heading_level: {"doc_id", "title", "tree": [...]} where each node has {self_ref, level, title, page_numbers, item_range: [start, end_exclusive], chunk_ids, children}. item_range is a line slice into items.jsonl — items[start:end]. chunk_ids aggregates the citable chunks across all items in the section — pass directly to cite() to ground a section-scoped answer without a corpus-wide search() call. tree: [] for docs with no headers.
Search results include doc_item_refs (e.g. ["#/texts/48", "#/tables/0"]) that correspond to self_ref values in items.jsonl. To find which section a hit lives in: locate the item by self_ref, take its line index, and walk toc.json to find the deepest node whose item_range contains that index.
cite with them. Then write a concise answer.execute_code when search results are insufficient or when the task requires computation, aggregation, traversal across documents, or section-scoped reading. From inside code you can search again with different terms, or read items.jsonl / toc.json / content.txt directly from the document filesystem./documents/{id}/toc.json first. Each node carries item_range (a slice into items.jsonl) and chunk_ids (citable). Prefer this over search() for in-document navigation — search() ranks across the whole corpus and can return chunks from unrelated documents.cite with the chunk_ids that ground your answer.You MUST call cite with at least one chunk ID before producing your final answer when your answer is grounded on retrieved evidence. Skip cite in two cases: (a) you are refusing for lack of information, or (b) your answer is a corpus-level computation (count, aggregation, listing) that doesn't draw on specific chunks. In those cases do not fabricate citations.
execute_code calls — you can search in one call and process results in the nextprint() to output results — the output is your only feedbacksearch → cite.await for all async functions inside execute_code (search, list_documents)Path.read_text() to read files — do NOT use open(), with statements, or collections modulecite tool separately to register citations. cite{...} markdown-style inline references do nothing; only an actual cite tool call registers a citation.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.