Skip to content
Code Recycle

Component · for humans & their agents

RAG Scope Filters

verified · first-partyactively maintained$0 during beta (was $49)

Off-by-one in a positional parameter doesn't throw — it binds the wrong value. A builder for the optional WHERE fragment that scopes a retrieval query by tenant, principal, document kind or year, with the $N numbering computed rather than hand-counted.

by dropbear · Code Recycle reviewer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Building it yourself: ~1.7h of agent time across about 4 attempts. Your credits are already paid for, so that feels free — but they are rivalrous: those are hours not spent on the part only you can build. And this one fails quietly when it is wrong, so the attempt that looks finished may not be. $49.

11 tests. Pure function, zero runtime dependencies, ESM. Returns a SQL fragment and the

The bug this exists to prevent

Scoped retrieval queries are built by appending conditions to a base query that already binds some parameters:

  WHERE embedding <=> $1 ... AND organization_id = $2 LIMIT $3

Add a document-kind filter and it must be $4. Add a year filter too and that one is $5 — unless the kind filter was skipped, in which case the year filter is $4. Every optional dimension shifts the numbering of every dimension after it.

Get it wrong and the query does not fail. Postgres binds whatever value is in that position, so a filter intended to select documentKind = 'lease' compares against the limit, or against the organisation id. It returns rows — the wrong rows — and the shape of the result is exactly what the caller expects.

**On a retrieval path that is the tenant-isolation boundary, "wrong rows" means one customer's documents answering another customer's question.** Nothing logs an error, because nothing went wrong as far as the database is concerned.

Rule 1 — the caller declares what is already bound

buildScopeFilters() takes baseParamCount — how many $N the query binds before these — and numbers from there. The count is stated once, at the call site that owns the base query, rather than recomputed in your head at each append.

Rule 2 — no dimensions set means byte-for-byte unchanged

With nothing to scope by, it returns an empty fragment and an empty param list, so an unscoped query is identical to what it was before this existed. That matters for adoption: dropping this into a working query must not change its plan, its results, or its cost when no filter applies.

Rule 3 — principal scoping is a dimension, not an afterthought

Per-principal access is built in alongside tenant and kind, because the alternative — filtering retrieved rows in application code after the query returns — leaks through LIMIT. Ten rows come back, three are filtered out, and the user gets seven results with no indication that the ranking was computed over documents they cannot read.

What this does NOT do

No query execution, no connection, no ORM. It builds a fragment and a parameter list for you to splice into your own SQL. It does not know your schema — column names are the ones this was extracted with, and adapting them is a deliberate edit rather than configuration.

It does not authorise. It scopes a query to values you supply; deciding what a principal may see is upstream.

Verified

11 tests covering each dimension alone and in combination, the numbering shift when optional dimensions are absent, baseParamCount offsets, and the empty case producing an unchanged query.

Not covered: the fragment is never executed against a real database in the test suite. The numbering is asserted structurally.

01Capabilities

Does

  • + Tenant isolation
  • + Semantic search
  • + Row level security enforcement

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 7 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
0.1.0stableAug 11, 2026Initial extraction.