known-problem-hint-research
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
references/exploit-hint-recipes.mdfile provides specific command-line templates for thesearchsploitutility (e.g.,searchsploit --cve {YYYY-NNNN},searchsploit -w {product} {version}). - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from a wide variety of untrusted external web sources (technical blogs, GitHub, research papers, exploit databases) to find technical solutions.
- Ingestion points: Data enters the agent context through
fetch_content,Tavily, andJina Reader/Searchendpoints as described inSKILL.mdandreferences/source-filters.md. - Boundary markers: The skill includes explicit "Quality rules" in
SKILL.mdthat instruct the agent to "Separate 'source says' from 'agent infers'" and "Do not outsource reasoning." - Capability inventory: The skill leverages web search tools, content fetchers, and command-line utilities for searching exploit databases.
- Sanitization: The instructions in
references/exploit-hint-recipes.mdadvise manual review of external code ("Read before running, isolate the environment") and prioritize extracting logic over executing untrusted code.
Audit Metadata