opensearch-docs
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to retrieve and process information from the official OpenSearch documentation website, which represents an external data ingestion surface.\n
- Ingestion points: External data is ingested from docs.opensearch.org via the agent's search and browsing capabilities as instructed in the skill workflow.\n
- Boundary markers: The instructions define a structured 'Answer Shape' and explicit citation requirements, but do not mandate the use of technical delimiters (such as XML tags or triple backticks) to wrap the external documentation content.\n
- Capability inventory: The skill uses tools to search and read web content. It does not contain instructions or scripts for file system modification, credential access, or arbitrary command execution.\n
- Sanitization: The skill relies on natural language instructions for grounding and verification rather than programmatic sanitization of the retrieved text.
Audit Metadata