research
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process information from external websites (via Firecrawl) and local source code, which introduces a surface for indirect prompt injection attacks.
- Ingestion points: SKILL.md (Step 2: Codebase Exploration and Step 3: External Research).
- Boundary markers: Absent; the instructions do not provide delimiters or specific guidance to ignore instructions embedded within the research material.
- Capability inventory: SKILL.md (Bash tool is enabled).
- Sanitization: Absent; the skill does not specify any filtering or validation of the content retrieved from external or local sources before it is synthesized into findings.
Audit Metadata