research
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved via web search tools, which represents a surface for indirect prompt injection attacks.\n
- Ingestion points: Web content fetched during the research fallback workflow.\n
- Capability inventory: Tool use (web search/fetch), local script execution, and document generation.\n
- Boundary markers: The skill enforces strict citation rules and explicitly differentiates between retrieved sources and background knowledge.\n
- Sanitization: Content synthesis is handled by the agent's reasoning process without explicit technical filtering described.\n- [EXTERNAL_DOWNLOADS]: The skill documentation notes a dependency on the standard Node.js
docxpackage for generating document-based reports, which is a legitimate dependency for its stated output capability.
Audit Metadata