skills/alpoxdev/hypercore/research/Gen Agent Trust Hub

research

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies research data as a primary attack surface and includes strong defensive instructions to ignore any commands or instructions found within retrieved sources (web pages, GitHub issues, local files). It mandates treating all external content strictly as evidence rather than instruction authority, which effectively mitigates Indirect Prompt Injection. Evidence of this protection is found in SKILL.md and rules/validation.md.
  • [DATA_EXFILTRATION]: While the skill accesses local repository data, its purpose is limited to internal research synthesis. Reports are saved to a dedicated local directory (.hyper/research/). No patterns for exfiltrating sensitive environment files or credentials to external domains were identified.
  • [REMOTE_CODE_EXECUTION]: The skill orchestrates parallel research via subagents. These subagents are provided with a 'read-only' prompt template that explicitly forbids file modifications, external side effects, or following instructions contained within the retrieved research content.
  • [SAFE]: The skill demonstrates high security awareness through its extensive validation rules, which include source grading, query deduplication, and mandatory citation coverage, ensuring that the synthesized information is verifiable and originating from authorized sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 11:03 AM
Security Audit — agent-trust-hub — research