deep-research
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core functionality of scraping and synthesizing data from external websites.
- Ingestion points: Untrusted data enters the agent context via
firecrawl_scrapeandcrawling_exatools as specified inSKILL.md(Step 4). - Boundary markers: There are no explicit instructions or delimiters defined to separate the scraped external content from the agent's internal instructions or to warn the agent to ignore commands within that content.
- Capability inventory: The skill allows the agent to write research reports to the local file system (Step 6) and launch parallel sub-agents via the Task tool, which could be exploited if an attacker-controlled website provides malicious instructions.
- Sanitization: The workflow does not describe any sanitization, filtering, or validation of the web content before it is used to generate the final report.
Audit Metadata