CtrlK
BlogDocsLog inGet started
Tessl Logo

rag-cag-security

Security patterns for RAG and CAG systems with multi-tenant isolation. Use when building retrieval-augmented or cache-augmented generation systems that require tenant isolation, access control, and secure data handling.

61

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./plugins/rag-cag/skills/rag-cag-security/SKILL.md
SKILL.md
Quality
Evals
Security

RAG/CAG Security Skill

This skill provides security patterns for RAG and CAG systems.

Multi-Tenant Architecture

Tenant Isolation Strategies

  1. Namespace Isolation - Separate vector namespaces per tenant
  2. Metadata Filtering - Filter by tenant_id at query time
  3. Separate Collections - Isolated collections per tenant
# Metadata filtering approach
results = vector_store.similarity_search(
    query,
    filter={"tenant_id": current_user.tenant_id}
)

Access Control

Document-Level Permissions

@dataclass
class Document:
    id: str
    content: str
    tenant_id: str
    access_groups: list[str]
    classification: str  # public, internal, confidential

def can_access(user: User, doc: Document) -> bool:
    return (
        user.tenant_id == doc.tenant_id
        and any(g in doc.access_groups for g in user.groups)
        and user.clearance >= doc.classification
    )

Prompt Injection Prevention

def sanitize_retrieved_context(chunks: list[str]) -> str:
    """Sanitize retrieved chunks before including in prompt."""
    sanitized = []
    for chunk in chunks:
        # Remove potential instruction patterns
        cleaned = remove_instruction_patterns(chunk)
        # Escape special characters
        escaped = escape_prompt_chars(cleaned)
        sanitized.append(escaped)
    return "\n".join(sanitized)

Data Classification

LevelDescriptionHandling
PublicOpen informationNo restrictions
InternalCompany-onlyTenant isolation
ConfidentialSensitiveEncryption + audit
RestrictedHighly sensitiveNeed-to-know basis

Security Checklist

  • Tenant isolation implemented
  • Document-level access control
  • Retrieved content sanitized
  • Audit logging enabled
  • Data encryption at rest
  • Secure API authentication
Repository
jpoutrin/product-forge
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.