answers
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external web search results, which presents a surface for indirect prompt injection.
- Ingestion points: Search result context and AI-synthesized responses are retrieved from the
api.search.brave.comAPI endpoint as described in SKILL.md. - Boundary markers: The response format utilizes structural tags including
<answer>,<citation>, and<thinking>to separate different data types. - Capability inventory: The skill is designed for network-based information retrieval and does not involve local file system writes or unauthorized command execution.
- Sanitization: The skill supports a
safesearchparameter to provide content filtering at the source API.- [SAFE]: The skill exclusively interacts with official Brave infrastructure and provides clear documentation for secure API key management using environment variables.
Audit Metadata