deep-research
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a standard and well-structured workflow for academic and industry research. It emphasizes source verification, handling conflicting information, and distinguishing between facts and analysis. No malicious patterns such as credential harvesting, unauthorized network access, or command execution were detected.
- [PROMPT_INJECTION]: The skill is a surface for indirect prompt injection because it instructs the agent to ingest untrusted data from the internet via
WebSearchandWebFetchtools (SKILL.md). Evidence: Data is fetched from external sources during the 'Research' phase; No explicit boundary markers or directives to ignore instructions within fetched content are provided; Capabilities include reading local files and writing output to the02-research/directory; Sanitization of external content is not explicitly mentioned. This is a common characteristic of research skills and is considered low risk in this context.
Audit Metadata