Works with the AI tools you already use
rag cross tenant leakage test pack
Security test suite for detecting cross-tenant data leakage in RAG retrieval and LLM memory phases.
$15
rag cross tenant leakage test pack
Example session with this skill installed
Run the leakage scorer on the latest test results from the staging environment using input.json and the synthetic fixtures for Tenant_402 and Tenant_909.
- Read your context and instructions
- Compiled the rag cross tenant
- Generated the document
I have processed the retrieval observations for Tenant_402 and Tenant_909. The analysis identifies a high-risk isolation failure during the warm cache phase.
RAG Isolation Security Report
| Phase | Tenant Context | Positive Control | Canary Detected | Status |
|---|---|---|---|---|
| Cold Cache | Tenant_402 | Found (Doc_A1) | None | PASS |
| Cold Cache | Tenant_909 | Found (Doc_B1) | None | PASS |
| Warm Cache | Tenant_402 | Found (Doc_A1) | Doc_B2 (Tenant_909) | FAIL |
| Warm Cache | Tenant_909 | Found (Doc_B1) | None | PASS |
| Active Memory | Tenant_402 | Found (Doc_A1) | None | PASS |
Findings Summary
- Evidence Provenance:
input.jsonv2.4.1,fixtures/synthetic_set_alpha.
Primary Violation: During the Warm Cache phase for Tenant_402, retrieval returned Doc_B2. This document belongs exclusively to Tenant_909.
Root Cause Analysis: The vector store retrieved cross-tenant embeddings when the index was warmed by Tenant_909's preceding query.
Positive Control Check: All positive controls were retrieved successfully, confirming that the leakage is not a result of indexing lag or service unavailability.
Next steps
- Inspect the metadata filtering logic in the retrieval adapter to ensure
tenant_idis strictly enforced at the query level. - Flush the vector cache and re-run the
scripts/check.pyto verify if the leak persists across fresh index loads. - Review the RAG orchestration layer for session-state pollution between Tenant_402 and Tenant_909.
rag-cross-tenant-leakage-test-pack.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
Multi-tenant RAG systems often leak data through shared vector caches, improper session handling, or flawed retrieval logic. Standard unit tests miss these runtime isolation failures occurring between the embedding and generation phases.
What it does
- Evaluates RAG outputs for cross-tenant canary leakage using synthetic document sets.
- Scores retrieval accuracy across cold cache, warm cache, and active memory phases.
- Identifies failures where Tenant A queries return citations or context from Tenant B.
- Verifies positive controls to ensure retrieval failures are due to isolation, not system downtime.
- Exports structured evidence reports suitable for security audits and compliance reviews.
Frameworks & tools
Compatible with RAG architectures using vector databases, LangChain, or custom retrieval adapters. Includes Python-based scoring scripts and JSON input contracts.
Why this beats prompting it yourself
General LLMs tend to hallucinate security, often assuming isolation exists when it doesn't. This skill enforces a strict evidence discipline that treats missing data as a failure rather than a pass, ensuring you don't get a false sense of security from "clean" logs.
Use cases
- Pre-production security validation for multi-tenant SaaS applications.
- Regression testing after updating vector database indexing or RLS policies.
- Auditing LLM memory persistence during rapid session switching.
- Generating compliance-ready evidence for data isolation requirements.
Known limitations
This is not a replacement for database-level Row Level Security (RLS) reviews. Requires synthetic test tenants and canaries; do not use with production data or customer secrets.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 13 days ago
- Passed all security checks, Safe to install
Needs access to