general-purpose
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill defines a research-to-action workflow that processes information from untrusted external sources and executes tasks using system-level capabilities, establishing an indirect prompt injection surface.
- Ingestion points: The agent is instructed to gather data from documentation, web resources, and GitHub repositories as detailed in SKILL.md.
- Boundary markers: There are no instructions for using delimiters or boundary markers to isolate instructions found within external data.
- Capability inventory: The agent is authorized to use
bashfor system operations and various file manipulation tools for task execution. - Sanitization: The methodology lacks requirements for data validation or sanitization of content retrieved from external sources.
- [NO_CODE]: The skill consists entirely of instructional markdown and does not include any accompanying scripts, executables, or code files.
Audit Metadata