cve-search
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources including CVE records, vendor advisories, and the OSV database, which creates a theoretical surface for indirect prompt injection if those records contain malicious instructions.
- Ingestion points: CVE.org, NVD, OSV, GHSA, and vendor advisory websites discovered via web access.
- Boundary markers: The skill defines a structured Markdown template for output entries but does not include explicit instructions for the agent to ignore or escape instructions potentially embedded within the fetched vulnerability descriptions.
- Capability inventory: The skill possesses the capability to write research findings to a user-specified file path (
dest_file). - Sanitization: There is no evidence of specific input sanitization, filtering, or escaping of retrieved external content before it is interpolated into the final report.
Audit Metadata