opensearch-docs

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to retrieve and process information from the official OpenSearch documentation website, which represents an external data ingestion surface.\n
  • Ingestion points: External data is ingested from docs.opensearch.org via the agent's search and browsing capabilities as instructed in the skill workflow.\n
  • Boundary markers: The instructions define a structured 'Answer Shape' and explicit citation requirements, but do not mandate the use of technical delimiters (such as XML tags or triple backticks) to wrap the external documentation content.\n
  • Capability inventory: The skill uses tools to search and read web content. It does not contain instructions or scripts for file system modification, credential access, or arbitrary command execution.\n
  • Sanitization: The skill relies on natural language instructions for grounding and verification rather than programmatic sanitization of the retrieved text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 11:52 AM
Security Audit — agent-trust-hub — opensearch-docs