research
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external 'primary sources' including documentation, source code, and first-party APIs, creating a potential surface for indirect prompt injection attacks where malicious instructions in those sources could influence the agent.
- Ingestion points: External documentation, source code repositories, and API specifications referenced during research tasks in
SKILL.md. - Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore embedded commands found within the external sources.
- Capability inventory: The agent has access to
Bash,Write, andTasktools, which enable it to execute commands and modify the repository based on gathered information. - Sanitization: No evidence of sanitization or validation protocols for the external content is specified before the data is integrated into the findings file.
Audit Metadata