research-analyst
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill defines workflows for ingesting untrusted data from external sources, which creates a surface for indirect prompt injection. 1. Ingestion points: External sources and documentation identified during workflows (SKILL.md). 2. Boundary markers: Absent; no delimiters are defined to isolate untrusted content from system instructions. 3. Capability inventory: Synthesis, cross-domain analysis, and narrative construction. 4. Sanitization: Absent; no validation logic for external content is provided.
- [NO_CODE]: This skill contains no executable scripts or code files and consists entirely of instructional markdown.
Audit Metadata