research-it
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted data from external sources via tools like
WebFetch. - Ingestion points: External documentation and primary references fetched during the "Search inward then outward" phase in SKILL.md.
- Boundary markers: The skill does not explicitly instruct the agent to use delimiters or ignore instructions found within external content.
- Capability inventory: The skill can trigger subagents, create issues (
issues create), and perform repository surveys. - Sanitization: No explicit sanitization or filtering of external content is described.
- [EXTERNAL_DOWNLOADS]: The skill workflow involves fetching external documentation and reputable references using the
WebFetchtool as described in the "Search inward then outward" section of SKILL.md.
Audit Metadata