skills/a-canary/arc-skills/research/Gen Agent Trust Hub

research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to gather data from external primary sources such as documentation, source code, and APIs using tools like WebFetch, gh api, npm view, and curl. Because the agent processes and summarizes this untrusted content to create a report, it is vulnerable to indirect prompt injection where an attacker could place malicious instructions inside the source material.
  • Ingestion points: External web content, documentation pages, GitHub API responses, and package metadata fetched via command-line tools.
  • Boundary markers: The instructions do not specify any delimiters or warnings to treat ingested content as data rather than instructions.
  • Capability inventory: The skill allows the agent to read external network resources and write findings to Markdown files within the repository.
  • Sanitization: There are no requirements for the agent to sanitize or filter the content retrieved from external sources before processing or writing it to the filesystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:02 AM
Security Audit — agent-trust-hub — research