deep-research-offensive

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and synthesize large amounts of data from external, untrusted sources such as security blogs, exploit repositories, and social media platforms, which may contain malicious instructions.
  • Ingestion points: External data enters the agent context via web searches (Tavily), reader tools (Jina), and browser scraping (Playwright), which is then saved to local files in the .research/ directory.
  • Boundary markers: The instructions do not define clear delimiters or "ignore instructions" warnings when the agent reads the stored files during the synthesis phase in Step 6.
  • Capability inventory: The skill has the capability to write and read files on the local system and execute browser scripts.
  • Sanitization: There is no mention of structural sanitization or instruction filtering for the fetched content beyond "removing boilerplate."
  • [EXTERNAL_DOWNLOADS]: The skill uses several third-party services and proxies to bypass anti-bot protections or retrieve social media data without authentication.
  • Services: It references the use of FxTwitter API, xcancel.com (a Twitter proxy), and tg.i-c-a.su (a Telegram proxy) to fetch JSON or HTML content.
  • [DYNAMIC_EXECUTION]: The skill provides static JavaScript recipes for the agent to execute via Playwright to scrape content from dynamic websites.
  • Evidence: Recipes for scraping Exploit-DB and xcancel search results are provided in SKILL.md and references/mcp-tools.md.
  • [COMMAND_EXECUTION]: The skill includes a local Python script intended for execution by the agent to interact with social media platforms.
  • Evidence: scripts/twitter_search.py is a CLI tool that uses the twikit library and accepts sensitive authentication credentials as command-line arguments to perform searches.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 02:21 PM
Security Audit — agent-trust-hub — deep-research-offensive