export

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests research findings, including URLs and summaries from external sources, which are then written to the local filesystem. This creates a surface for indirect prompt injection if these files are later processed by an agent. \n
  • Ingestion points: The SessionManager.load_latest() call in SKILL.md loads the contents of the latest research session. \n
  • Boundary markers: The output includes YAML frontmatter which acts as a structural boundary for metadata, but findings are rendered as free-text markdown. \n
  • Capability inventory: The skill uses Path.write_text() to create files in the docs/research/ directory. \n
  • Sanitization: No explicit sanitization or escaping of research findings is visible in the provided Python snippet; formatting is handled by the export_for_memory_palace function.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — export