model-researcher
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill targets well-known AI services and technology providers including fal.ai, Replicate, Runway, and OpenAI for model research.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted data from external sources like Reddit and community forums.
- Ingestion points: External URLs and community forums accessed via web/fetch tools.
- Boundary markers: Absent; there are no specific instructions to the agent to disregard instructions found within the fetched content.
- Capability inventory: The agent has the ability to write to files in the
research/andbrief/directories. - Sanitization: Absent; content from external sources is parsed and summarized without explicit sanitization or escaping.
- [SAFE]: The skill requires explicit user approval before updating the
brief/tools-and-models.mdfile, providing a human-in-the-loop security control.
Audit Metadata