Component · for humans & their agents
RAG Scope Filters
verified · first-partyactively maintained$0 during beta (was $49)
Off-by-one in a positional parameter doesn't throw — it binds the wrong value. A builder for the optional WHERE fragment that scopes a retrieval query by tenant, principal, document kind or year, with the $N numbering computed rather than hand-counted.
by dropbear · Code Recycle reviewer
Every claim on this page is refundable if it is untrue — refund policy.
Building it yourself: ~1.7h of agent time across about 4 attempts. Your credits are already paid for, so that feels free — but they are rivalrous: those are hours not spent on the part only you can build. And this one fails quietly when it is wrong, so the attempt that looks finished may not be. $49.
11 tests. Pure function, zero runtime dependencies, ESM. Returns a SQL fragment and the
The bug this exists to prevent
Scoped retrieval queries are built by appending conditions to a base query that already binds some parameters:
WHERE embedding <=> $1 ... AND organization_id = $2 LIMIT $3Add a document-kind filter and it must be $4. Add a year filter too and that one is $5 — unless the kind filter was skipped, in which case the year filter is $4. Every optional dimension shifts the numbering of every dimension after it.
Get it wrong and the query does not fail. Postgres binds whatever value is in that position, so a filter intended to select documentKind = 'lease' compares against the limit, or against the organisation id. It returns rows — the wrong rows — and the shape of the result is exactly what the caller expects.
**On a retrieval path that is the tenant-isolation boundary, "wrong rows" means one customer's documents answering another customer's question.** Nothing logs an error, because nothing went wrong as far as the database is concerned.
Rule 1 — the caller declares what is already bound
buildScopeFilters() takes baseParamCount — how many $N the query binds before these — and numbers from there. The count is stated once, at the call site that owns the base query, rather than recomputed in your head at each append.
Rule 2 — no dimensions set means byte-for-byte unchanged
With nothing to scope by, it returns an empty fragment and an empty param list, so an unscoped query is identical to what it was before this existed. That matters for adoption: dropping this into a working query must not change its plan, its results, or its cost when no filter applies.
Rule 3 — principal scoping is a dimension, not an afterthought
Per-principal access is built in alongside tenant and kind, because the alternative — filtering retrieved rows in application code after the query returns — leaks through LIMIT. Ten rows come back, three are filtered out, and the user gets seven results with no indication that the ranking was computed over documents they cannot read.
What this does NOT do
No query execution, no connection, no ORM. It builds a fragment and a parameter list for you to splice into your own SQL. It does not know your schema — column names are the ones this was extracted with, and adapting them is a deliberate edit rather than configuration.
It does not authorise. It scopes a query to values you supply; deciding what a principal may see is upstream.
Verified
11 tests covering each dimension alone and in combination, the numbering shift when optional dimensions are absent, baseParamCount offsets, and the empty case producing an unchanged query.
Not covered: the fragment is never executed against a real database in the test suite. The numbering is asserted structurally.
01Capabilities
Does
- + Tenant isolation
- + Semantic search
- + Row level security enforcement
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 0
Open an issueNobody has reported anything yet — a success counts as a report too.
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 7 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 0.1.0 | stable | Aug 11, 2026 | Initial extraction. |