research-intelligence
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts including
tools/evidence_lineage_check.py,tools/source_reach_doctor.py, andtools/youtube_research.pyto manage evidence lineages and verify source availability. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the public web, social media platforms, and external document files, creating a vulnerability surface for embedded malicious instructions.
- Ingestion points: Data is collected from web search results, GitHub/npm/PyPI APIs, Reddit, RSS feeds, and document formats (PDF, DOCX, XLSX) as defined in the 'Source Ladder'.
- Boundary markers: The instructions implement an 'Evidence Gate' and specific research modes (
references/research-modes.md) to categorize content into facts, claims, and hypotheses, aiding the agent in distinguishing source content from instructions. - Capability inventory: The skill possesses the capability to execute subprocesses (local Python scripts) and perform network read operations using various research tools.
- Sanitization: No automated sanitization or filtering of external content is described; the skill relies on the agent's manual grading of evidence signal strength to mitigate risks.
Audit Metadata