feynman-perspective
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's research protocol (defined in Step 2 of the Answer Workflow) requires the agent to utilize web search tools to gather real-world facts, data, and technical principles. This ingestion of untrusted external data into the agent's context presents a vulnerability surface for indirect prompt injection attacks where malicious content on search-indexed pages could attempt to influence the agent's behavior.
- Ingestion points: WebSearch tool output processed during the 'Step 2: Feynman-style Research' phase in
SKILL.md. - Boundary markers: Absent; the instructions do not define protective delimiters or specific warnings to ignore embedded instructions within retrieved search data.
- Capability inventory: Uses standard platform search tools. No custom scripts, file system writes, or subprocess executions are included in the skill package.
- Sanitization: Absent; the workflow does not specify any sanitization or validation of content retrieved from the web before it is incorporated into the response logic.
Audit Metadata