answers

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web search results, which presents a surface for indirect prompt injection.
  • Ingestion points: Search result context and AI-synthesized responses are retrieved from the api.search.brave.com API endpoint as described in SKILL.md.
  • Boundary markers: The response format utilizes structural tags including <answer>, <citation>, and <thinking> to separate different data types.
  • Capability inventory: The skill is designed for network-based information retrieval and does not involve local file system writes or unauthorized command execution.
  • Sanitization: The skill supports a safesearch parameter to provide content filtering at the source API.- [SAFE]: The skill exclusively interacts with official Brave infrastructure and provides clear documentation for secure API key management using environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:27 PM
Security Audit — agent-trust-hub — answers