export
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests research findings, including URLs and summaries from external sources, which are then written to the local filesystem. This creates a surface for indirect prompt injection if these files are later processed by an agent. \n
- Ingestion points: The
SessionManager.load_latest()call inSKILL.mdloads the contents of the latest research session. \n - Boundary markers: The output includes YAML frontmatter which acts as a structural boundary for metadata, but findings are rendered as free-text markdown. \n
- Capability inventory: The skill uses
Path.write_text()to create files in thedocs/research/directory. \n - Sanitization: No explicit sanitization or escaping of research findings is visible in the provided Python snippet; formatting is handled by the
export_for_memory_palacefunction.
Audit Metadata