brief-remote-friendliness

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core function of processing untrusted web content.
  • Ingestion points: Data is gathered from external websites, engineering blogs, and social media platforms using WebSearch and WebFetch tools.
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to prevent the agent from executing instructions potentially found in the fetched job descriptions or blog posts.
  • Capability inventory: The agent has access to Write and Bash tools, allowing it to modify the local filesystem based on the research results.
  • Sanitization: No sanitization or validation of the fetched external text is mentioned before the agent uses it to generate the final report.
  • [EXTERNAL_DOWNLOADS]: The skill fetches content from external web services like LinkedIn and various corporate domains. These are well-known platforms and are consistent with the skill's stated research purpose.
  • [COMMAND_EXECUTION]: The skill uses restricted Bash commands including mkdir and test to manage the local directory structure for storing research output.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 05:16 AM
Security Audit — agent-trust-hub — brief-remote-friendliness