deep-research
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and synthesize untrusted external data from the open web.
- Ingestion points: The instructions specify using
agent-browserto read full-text articles and retrieve content from external websites (SKILL.md). - Boundary markers: The instructions lack explicit directives for the agent to use delimiters or ignore potential instructions embedded within the retrieved web content.
- Capability inventory: The skill utilizes
multi-search-engine,pubmed-search, andagent-browserto find, read, and process external information. - Sanitization: There are no instructions for sanitizing or validating external content before it is integrated into the agent's context and final report.
Audit Metadata