best-practices-research
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill utilizes web search tools like Exa or built-in WebSearch to retrieve technical data, which is appropriate for its stated function of technical research.
- [SAFE]: A security boundary is established by instructing subagents to 'Research and report only' and explicitly prohibiting 'file edits' during the reconnaissance phase.
- [SAFE]: The skill processes external data from the web, creating an indirect prompt injection surface; however, the structured workflow requiring the agent to reconcile findings and note sources for recommendations mitigates the risk.
- Ingestion points: web_search_exa, WebSearch, and WebFetch tools referenced in SKILL.md.
- Boundary markers: Absent (though research constraints are specified).
- Capability inventory: Subagents are configured as 'write-capable' (foreground) to access MCP/internet tools, and the main agent integrates results into the final code implementation.
- Sanitization: Absent.
Audit Metadata