search-first

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a workflow that ingests research data from external untrusted sources (web, GitHub, and package registries). This presents an indirect prompt injection surface where malicious instructions hidden in third-party content could influence the agent's behavior. Ingestion points: Research results fetched via the researcher agent; Boundary markers: Absent in the provided prompt template; Capability inventory: The skill allows for file writes, package installations, and code implementation based on research; Sanitization: No sanitization or validation of the retrieved external content is specified.
  • [DATA_EXFILTRATION]: Instructions to check ~/.claude/settings.json and ~/.claude/skills/ for tool discovery involve accessing local configuration data. While intended for discovery of MCP servers and skills, these files may contain sensitive environment or integration details.
  • [COMMAND_EXECUTION]: The workflow directs the agent to install and use third-party packages (e.g., via npm install or pip install) discovered through research, which relies on the agent's ability to verify the safety and integrity of external software.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:10 AM
Security Audit — agent-trust-hub — search-first