deep-research

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a complex orchestration of agent personas for academic research tasks. It does not contain any executable scripts, binaries, or shell commands that could be leveraged for malicious purposes.
  • [EXTERNAL_DOWNLOADS]: The skill references and provides instructions for interacting with well-known and reputable academic services, including Google Scholar, PubMed, arXiv, and Retraction Watch. These are standard tools in the research community and are treated as safe based on the trusted technology companies and academic services recognition rule.
  • [DATA_EXFILTRATION]: There are no patterns suggesting the access or exfiltration of sensitive local data (e.g., SSH keys, environment variables, or cloud credentials). The data processing is limited to academic literature and user-provided research topics.
  • [PROMPT_INJECTION]: The instructions include robust persona constraints, specifically for the Socratic Mentor agent, which is directed to guide users through questioning rather than providing direct answers. This supports the intended use case and prevents simple bypasses of the educational framework.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or other sensitive credentials were found in the skill's files. The skill correctly instructs users on how to manage their own research environment safely and refers to standard academic identifiers like DOIs and ORCIDs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 11:31 AM
Security Audit — agent-trust-hub — deep-research