model-researcher

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill targets well-known AI services and technology providers including fal.ai, Replicate, Runway, and OpenAI for model research.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from external sources like Reddit and community forums.
  • Ingestion points: External URLs and community forums accessed via web/fetch tools.
  • Boundary markers: Absent; there are no specific instructions to the agent to disregard instructions found within the fetched content.
  • Capability inventory: The agent has the ability to write to files in the research/ and brief/ directories.
  • Sanitization: Absent; content from external sources is parsed and summarized without explicit sanitization or escaping.
  • [SAFE]: The skill requires explicit user approval before updating the brief/tools-and-models.md file, providing a human-in-the-loop security control.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 04:27 PM
Security Audit — agent-trust-hub — model-researcher