deep-research-generic
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content fetched from arbitrary external websites, which serves as a potential ingestion point for indirect prompt injection attacks.
- Ingestion points: Data enters the system from external URLs and is saved as markdown files within the
.research/{topic-slug}/pages/directory. - Boundary markers: The instructions do not define strict boundary markers or specific "ignore embedded instructions" warnings, relying instead on high-level content cleaning directives.
- Capability inventory: The skill possesses capabilities for file system writes (to create research logs) and invocation of network tools (search, fetch, and browser automation).
- Sanitization: The methodology includes a step to strip navigation, ads, and boilerplate from fetched content, which acts as a rudimentary filter for external data.
- [EXTERNAL_DOWNLOADS]: The skill utilizes external search engines and fetch tools (such as Tavily and generic page-fetch APIs) to retrieve content from the internet as its primary operation.
- [COMMAND_EXECUTION]: The workflow involves the use of browser automation tools like Playwright to process dynamic or JavaScript-heavy web pages when standard fetching methods fail.
Audit Metadata