research
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest content from external primary sources, creating a surface where malicious instructions embedded in documentation could influence the agent's output.
- Ingestion points: The skill reads official documentation, source code, specifications, and first-party APIs as defined in SKILL.md.
- Boundary markers: No explicit delimiters or ignore-instruction warnings are specified to isolate the external content from the agent's internal instructions.
- Capability inventory: The agent has the capability to write research results to Markdown files within the local repository.
- Sanitization: There are no instructions for the agent to sanitize, escape, or validate the content retrieved from primary sources before saving it to the file system.
Audit Metadata