gds-domain-research
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python utility script (
_bmad/scripts/resolve_customization.py) to manage workflow configuration merging and overrides. Evidence of this execution is found in SKILL.md and step-06-research-synthesis.md.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from web search results to generate a research report, which presents a surface for indirect prompt injection.\n - Ingestion points: Web search results are gathered and processed in step-02-domain-analysis.md, step-03-competitive-landscape.md, step-04-regulatory-focus.md, step-05-technical-trends.md, and step-06-research-synthesis.md.\n
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore potential commands embedded within the retrieved external content.\n
- Capability inventory: The skill can perform web searches (step-02), write to local research files (SKILL.md, step-02, and step-06), and execute local Python scripts (SKILL.md and step-06-research-synthesis.md).\n
- Sanitization: There is no evidence of sanitization, filtering, or validation for the data retrieved from external websites before it is aggregated into the research report.
Audit Metadata