gds-domain-research

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python utility script (_bmad/scripts/resolve_customization.py) to manage workflow configuration merging and overrides. Evidence of this execution is found in SKILL.md and step-06-research-synthesis.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from web search results to generate a research report, which presents a surface for indirect prompt injection.\n
  • Ingestion points: Web search results are gathered and processed in step-02-domain-analysis.md, step-03-competitive-landscape.md, step-04-regulatory-focus.md, step-05-technical-trends.md, and step-06-research-synthesis.md.\n
  • Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded within the retrieved external content.\n
  • Capability inventory: The skill can perform web searches (step-02), write to local research files (SKILL.md, step-02, and step-06), and execute local Python scripts (SKILL.md and step-06-research-synthesis.md).\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation for the data retrieved from external websites before it is aggregated into the research report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 08:01 PM
Security Audit — agent-trust-hub — gds-domain-research