skills/chann/skills/research-brief/Gen Agent Trust Hub

research-brief

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core functionality requires the agent to ingest and process data from third-party external sources, including documentation, source code, and community forums. This creates a surface for indirect prompt injection, where an attacker could place malicious instructions within technical content to influence the agent's behavior during the reading phase.
  • Ingestion points: The agent reads from external T1 (specifications, source code), T2 (changelogs, official blogs), and T3 (community forums, third-party blogs) sources as defined in Section 3 of SKILL.md.
  • Boundary markers: While the skill mandates a structured output format for the final brief (Section 6), it does not provide specific instructions for using delimiters or boundary markers when the agent is processing raw data from external sources.
  • Capability inventory: The skill instructions allow the agent to write research artifacts to the local .research/ directory and perform network-read operations via the platform's browser or background agent capabilities.
  • Sanitization: The instructions focus on verification and citation tiers but do not specify procedures for sanitizing, escaping, or filtering content retrieved from external sources before the agent interprets it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 02:04 PM
Security Audit — agent-trust-hub — research-brief