web-research-assistant

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/research.py uses a dynamic import (__import__('datetime')) to retrieve the current time for generating reports. This is a standard programming pattern and, in this context, does not present a security risk as it targets a standard library and involves no user-controlled input.
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from the internet (snippets and titles) and includes them in research reports. While this introduces a surface for indirect prompt injection, it is the primary intended function of a research assistant. The impact is minimal as the data is used for report generation.
  • Ingestion point: Web search results from the BrowserAct API (processed in scripts/research.py).
  • Boundary markers: None explicitly used in the script for the report content.
  • Capability inventory: File writing (via --output flag in scripts/research.py).
  • Sanitization: None performed on the extracted snippets before interpolation into the markdown report.
  • [DATA_EXFILTRATION]: The script transmits an API token to mcp.browseract.com. As this domain is associated with the skill's author (browser-act), this is documented as standard API communication rather than unauthorized exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — web-research-assistant