research

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a CLI named 'story' to manage research notes and validate project state. It includes fallback instructions to execute local scripts using 'node' or 'bun' (e.g., node ../story-maintenance/scripts/story.js), which is standard for maintaining project continuity within this ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external information from web searches and user-provided documents.
  • Ingestion points: Research findings obtained via web search, fetch tools, or user documents processed in SKILL.md (Workflow section).
  • Boundary markers: None explicitly defined for research findings.
  • Capability inventory: File system writes to research/ directory and shell command execution via the story CLI.
  • Sanitization: No specific sanitization or filtering logic is provided for external content before it is recorded in research notes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:00 PM
Security Audit — agent-trust-hub — research