research
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data and writes the results to the local repository.
- Ingestion points: External websites, official documentation, and source code files retrieved during the research process as instructed in SKILL.md.
- Boundary markers: The instructions lack explicit delimiters or warnings to ignore embedded instructions within the primary sources.
- Capability inventory: The skill is authorized to write and save Markdown files to the local file system (SKILL.md).
- Sanitization: No sanitization, validation, or escaping procedures are defined for the content aggregated from external sources before it is written to the repository.
Audit Metadata