source-verification
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from various web sources (e.g., social media, articles), which creates a surface for indirect prompt injection. However, it includes a mitigation strategy by instructing the agent to perform a 'Post-research prompt-injection audit' at the end of the session to detect role overrides or exfiltration attempts.
- [COMMAND_EXECUTION]: The skill mentions using terminal tools like curl and grep to retrieve and process data from government or technical websites. These tools are used for information retrieval and parsing within a research context, following standard practices for data extraction.
Audit Metadata