deep-research

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The instructions across all 13 agents and the primary SKILL.md follow a highly structured academic orchestration pattern. No attempts to override safety filters, bypass instructions, or execute role-play jailbreaks (like DAN) were detected. The 'Socratic Mode' uses intent detection for pedagogical purposes rather than instruction override.
  • [DATA_EXFILTRATION]: The skill mentions external network access for legitimate academic research purposes, such as searching Google Scholar, PubMed, and Crossref (DOI verification). No hardcoded credentials, sensitive file path accesses (~/.ssh, .env), or suspicious data exfiltration patterns were found. It contains robust guides for data de-identification and privacy protection (references/irb_decision_tree.md).
  • [REMOTE_CODE_EXECUTION]: There is no evidence of remote code execution or fetching untrusted scripts from the internet. Software references are limited to well-known academic packages in R (metafor, meta, dmetar) and Python (statsmodels) used for statistical meta-analysis.
  • [COMMAND_EXECUTION]: No shell commands, subprocess spawning, or direct system calls are present in the provided skill files. The 'monitoring_agent' generates templates and configurations for users rather than executing autonomous background processes.
  • [DATA_EXPOSURE]: The skill explicitly teaches and enforces safe data handling practices, including human-subjects ethics review (IRB) and de-identification strategies (anonymization/pseudonymization), which mitigates accidental data exposure.
  • [SAFE]: The skill's author context (brycewang-stanford) aligns with the academic and technical nature of the content. All external URLs point to well-known academic repositories and technology services (e.g., OSF, PubMed, arXiv, GitHub/anthropics).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 03:11 AM
Security Audit — agent-trust-hub — deep-research