deep-research

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and synthesize untrusted external data from the open web.
  • Ingestion points: The instructions specify using agent-browser to read full-text articles and retrieve content from external websites (SKILL.md).
  • Boundary markers: The instructions lack explicit directives for the agent to use delimiters or ignore potential instructions embedded within the retrieved web content.
  • Capability inventory: The skill utilizes multi-search-engine, pubmed-search, and agent-browser to find, read, and process external information.
  • Sanitization: There are no instructions for sanitizing or validating external content before it is integrated into the agent's context and final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 11:29 PM
Security Audit — agent-trust-hub — deep-research