deep-research
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions across all 13 agents and the primary SKILL.md follow a highly structured academic orchestration pattern. No attempts to override safety filters, bypass instructions, or execute role-play jailbreaks (like DAN) were detected. The 'Socratic Mode' uses intent detection for pedagogical purposes rather than instruction override.
- [DATA_EXFILTRATION]: The skill mentions external network access for legitimate academic research purposes, such as searching Google Scholar, PubMed, and Crossref (DOI verification). No hardcoded credentials, sensitive file path accesses (~/.ssh, .env), or suspicious data exfiltration patterns were found. It contains robust guides for data de-identification and privacy protection (references/irb_decision_tree.md).
- [REMOTE_CODE_EXECUTION]: There is no evidence of remote code execution or fetching untrusted scripts from the internet. Software references are limited to well-known academic packages in R (metafor, meta, dmetar) and Python (statsmodels) used for statistical meta-analysis.
- [COMMAND_EXECUTION]: No shell commands, subprocess spawning, or direct system calls are present in the provided skill files. The 'monitoring_agent' generates templates and configurations for users rather than executing autonomous background processes.
- [DATA_EXPOSURE]: The skill explicitly teaches and enforces safe data handling practices, including human-subjects ethics review (IRB) and de-identification strategies (anonymization/pseudonymization), which mitigates accidental data exposure.
- [SAFE]: The skill's author context (brycewang-stanford) aligns with the academic and technical nature of the content. All external URLs point to well-known academic repositories and technology services (e.g., OSF, PubMed, arXiv, GitHub/anthropics).
Audit Metadata