research-intelligence

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts including tools/evidence_lineage_check.py, tools/source_reach_doctor.py, and tools/youtube_research.py to manage evidence lineages and verify source availability.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from the public web, social media platforms, and external document files, creating a vulnerability surface for embedded malicious instructions.
  • Ingestion points: Data is collected from web search results, GitHub/npm/PyPI APIs, Reddit, RSS feeds, and document formats (PDF, DOCX, XLSX) as defined in the 'Source Ladder'.
  • Boundary markers: The instructions implement an 'Evidence Gate' and specific research modes (references/research-modes.md) to categorize content into facts, claims, and hypotheses, aiding the agent in distinguishing source content from instructions.
  • Capability inventory: The skill possesses the capability to execute subprocesses (local Python scripts) and perform network read operations using various research tools.
  • Sanitization: No automated sanitization or filtering of external content is described; the skill relies on the agent's manual grading of evidence signal strength to mitigate risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:03 AM
Security Audit — agent-trust-hub — research-intelligence