deep-research

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of scraping and synthesizing data from external websites.
  • Ingestion points: Untrusted data enters the agent context via firecrawl_scrape and crawling_exa tools as specified in SKILL.md (Step 4).
  • Boundary markers: There are no explicit instructions or delimiters defined to separate the scraped external content from the agent's internal instructions or to warn the agent to ignore commands within that content.
  • Capability inventory: The skill allows the agent to write research reports to the local file system (Step 6) and launch parallel sub-agents via the Task tool, which could be exploited if an attacker-controlled website provides malicious instructions.
  • Sanitization: The workflow does not describe any sanitization, filtering, or validation of the web content before it is used to generate the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — deep-research