deep-research-generic

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes content fetched from arbitrary external websites, which serves as a potential ingestion point for indirect prompt injection attacks.
  • Ingestion points: Data enters the system from external URLs and is saved as markdown files within the .research/{topic-slug}/pages/ directory.
  • Boundary markers: The instructions do not define strict boundary markers or specific "ignore embedded instructions" warnings, relying instead on high-level content cleaning directives.
  • Capability inventory: The skill possesses capabilities for file system writes (to create research logs) and invocation of network tools (search, fetch, and browser automation).
  • Sanitization: The methodology includes a step to strip navigation, ads, and boilerplate from fetched content, which acts as a rudimentary filter for external data.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes external search engines and fetch tools (such as Tavily and generic page-fetch APIs) to retrieve content from the internet as its primary operation.
  • [COMMAND_EXECUTION]: The workflow involves the use of browser automation tools like Playwright to process dynamic or JavaScript-heavy web pages when standard fetching methods fail.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:20 PM
Security Audit — agent-trust-hub — deep-research-generic