search
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes search results from the public web, which are untrusted third-party inputs that may contain malicious instructions.
- Ingestion points: Untrusted data enters the agent context through search result titles, URLs, and metadata retrieved via
curlcalls inSKILL.mdandEXAMPLES.md. - Boundary markers: The skill includes explicit "Safety Notes" in
SKILL.md,EXAMPLES.md, andREFERENCE.mdwarning the agent to treat results as untrusted remote input. - Capability inventory: The skill uses the
Bashtool to perform network requests, parse JSON withjq, and manipulate strings withsed. - Sanitization: While the skill uses
jqfor structured parsing, the provided examples demonstrate shell interpolation of search results into commands and file system paths, relying on the LLM's adherence to the safety instructions for security. - [COMMAND_EXECUTION]: The skill uses the
Bashtool to interact with the Search API and perform post-processing of results. - Evidence: Multiple examples in
SKILL.mdandEXAMPLES.mdutilizecurl,jq, shell pipes, and redirection to local files to manage the search workflow. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to external endpoints to facilitate searching and fetching content.
- Evidence: The skill performs POST requests to
https://api.browserbase.com/v1/searchandhttps://api.browserbase.com/v1/fetch. These destinations correspond to the skill author's official infrastructure.
Audit Metadata